
One Click Close Comments Security & Risk Analysis
wordpress.org/plugins/one-click-close-commentsConveniently close or open comments for a post or page with one click from the admin listing of posts.
Is One Click Close Comments Safe to Use in 2026?
Generally Safe
Score 91/100One Click Close Comments has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "one-click-close-comments" v3.0 plugin exhibits a generally strong security posture based on the provided static analysis. The complete absence of detectable attack surface entry points such as AJAX handlers, REST API routes, shortcodes, and cron events is a significant positive. Furthermore, the code demonstrates good practices with 100% of SQL queries utilizing prepared statements, all output being properly escaped, and the presence of nonce and capability checks. There are no indications of dangerous functions, file operations, or external HTTP requests, which are common vectors for exploitation.
Despite the promising static analysis, a historical vulnerability of "Exposure of Sensitive Information to an Unauthorized Actor" with a medium severity is noted, with the last instance occurring very recently. While this specific vulnerability is currently unpatched, the fact that it's the only reported CVE and it's marked as unpatched (although the data states 'Currently unpatched: 0' but then lists a recent vulnerability) warrants attention. This suggests a potential for undiscovered vulnerabilities or a recurring pattern of security weaknesses that, while not critical, could still pose a risk. The absence of taint analysis results in this specific run is neutral, but combined with the historical vulnerability, it's prudent to be cautiously optimistic.
In conclusion, the plugin's codebase for v3.0 appears robust and follows many security best practices. However, the presence of a past medium-severity vulnerability, particularly one related to information exposure, cannot be ignored. While the current code shows no immediate red flags, the historical context suggests that vigilance and potentially more in-depth security testing, beyond this static analysis snapshot, would be beneficial to ensure ongoing security.
Key Concerns
- Recent medium severity vulnerability reported
One Click Close Comments Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
One Click Close Comments <= 2.7.1 - Unauthenticated Full Path Disclosure
One Click Close Comments Release Timeline
One Click Close Comments Code Analysis
Output Escaping
One Click Close Comments Attack Surface
WordPress Hooks 10
Maintenance & Trust
One Click Close Comments Maintenance & Trust
Maintenance Signals
Community Trust
One Click Close Comments Alternatives
KD Submissions
kd-submissions
An intuitive WordPress plugin for managing submissions created by Elementor Submissions, statuses, comments, and WHMCS analytics sync. ---
Show Pending Comments Count
show-pending-comments-count
Display the pending comments count next to the approved comments count in the admin listing of posts.
Relative URL
relative-url
Relative URL applies wp_make_link_relative function to links to convert them to relative URLs.
Quotmarks Replacer
quotmarks-replacer
Quotmarks Replacer disables wptexturize function that keeps all quotation marks and suspension points in half-width form.
Nofollow Case by Case
nofollow-case-by-case
"Dofollow" but Nofollow Case by Case allows you to selectively apply nofollow to your comments as well.
One Click Close Comments Developer Profile
63 plugins · 92K total installs
How We Detect One Click Close Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/one-click-close-comments/css/style.css/wp-content/plugins/one-click-close-comments/js/script.js/wp-content/plugins/one-click-close-comments/js/script.jsone-click-close-comments/css/style.css?ver=one-click-close-comments/js/script.js?ver=HTML / DOM Fingerprints
comment_statedata-post-idc2c_one_click_close_comments_ajax_urlc2c_one_click_close_comments_noncec2c_one_click_close_comments_post_idc2c_one_click_close_comments_fieldc2c_one_click_close_comments_field_titlec2c_one_click_close_comments_help_text+1 more