
Paged Comments Security & Risk Analysis
wordpress.org/plugins/paged-commentsPaged Comments enables comment paging. Useful for those popular blog entries receiving many comments, or a simple guestbook page within WordPress.
Is Paged Comments Safe to Use in 2026?
Generally Safe
Score 85/100Paged Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "paged-comments" v2.9.1 plugin, despite its age, exhibits a generally weak security posture primarily due to a lack of fundamental security practices. While there are no recorded CVEs and the static analysis reveals no critical vulnerabilities in terms of dangerous functions, AJAX handlers, REST API routes, or shortcodes, the code analysis flags significant concerns. Specifically, all SQL queries are executed without prepared statements, posing a risk of SQL injection. Furthermore, a staggering 92 output operations lack proper escaping, creating a high probability of Cross-Site Scripting (XSS) vulnerabilities. The presence of a single file operation without context also warrants attention. The taint analysis, though limited, points to at least one flow involving unsanitized paths, which could be exploited if it interacts with user-supplied input. The complete absence of nonce and capability checks across the entire plugin is a critical oversight, leaving any potential entry points (though currently none are identified) completely unprotected. The vulnerability history being clear might be a reflection of its limited complexity or the fact that it hasn't been actively targeted or analyzed by security researchers over time, rather than an indication of robust security. In conclusion, while the plugin appears to have a small attack surface and no known exploitable vulnerabilities, the underlying coding practices are concerning and present a clear risk of exploitation if new entry points were to be introduced or if existing functions were to be exposed differently.
Key Concerns
- SQL queries not using prepared statements
- No proper output escaping
- No nonce checks implemented
- No capability checks implemented
- Taint flow with unsanitized paths
Paged Comments Security Vulnerabilities
Paged Comments Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Paged Comments Attack Surface
WordPress Hooks 5
Maintenance & Trust
Paged Comments Maintenance & Trust
Maintenance Signals
Community Trust
Paged Comments Alternatives
Paginated Comments
paginated-comments
Breaks down comments into a number of search engine optimized pages.
jQuery Post Splitter
jquery-post-splitter
This plugin will split your post and pages into multiple pages with a tag. A button to split the pages and posts is available in text editor icons.
BH Pagination
bh-pagination
This is simple pagination pugin for wordpress template.
easyCommentsPaginate
easycommentspaginate
easyCommentsPaginate is a plugin to easily create nice animated pagination for your comments
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Paged Comments Developer Profile
2 plugins · 150 total installs
How We Detect Paged Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/paged-comments/css/style.css/wp-content/plugins/paged-comments/js/paged-comments.js/wp-content/plugins/paged-comments/js/paged-comments.jspaged-comments/css/style.css?ver=paged-comments/js/paged-comments.js?ver=HTML / DOM Fingerprints
window.paged_comments