Paginated Comments Security & Risk Analysis

wordpress.org/plugins/paginated-comments

Breaks down comments into a number of search engine optimized pages.

20 active installs v1.0.6 PHP + WP + Updated Unknown
commentsmultiple-commentspaged-commentspaginated-commentssplit-comments
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Paginated Comments Safe to Use in 2026?

Generally Safe

Score 100/100

Paginated Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The paginated-comments plugin v1.0.6 exhibits a generally good security posture due to its use of prepared statements for all SQL queries and a limited attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. The presence of a nonce check and a capability check further enhances its security. However, concerns arise from the output escaping, where only 38% of the 50 total outputs are properly escaped, indicating a potential risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is rendered without adequate sanitization. Additionally, a taint analysis revealed one flow with an unsanitized path, which could lead to local file inclusion or other path traversal issues, although it was not classified as critical or high severity. The plugin's history of zero known CVEs is a positive indicator, suggesting a history of responsible development. Overall, while the plugin benefits from a small attack surface and secure database interactions, the lack of comprehensive output escaping and the presence of an unsanitized path flow present moderate risks that should be addressed.

Key Concerns

  • Output escaping is low (38%)
  • Taint analysis shows unsanitized path flow
Vulnerabilities
None known

Paginated Comments Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Paginated Comments Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
10 prepared
Unescaped Output
31
19 escaped
Nonce Checks
1
Capability Checks
1
File Operations
2
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared10 total queries

Output Escaping

38% escaped50 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
Paginated_Comments_heads (paginated-comments.php:505)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Paginated Comments Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
filterwp_titlepaginated-comments.php:454
filterthe_contentpaginated-comments.php:467
actioninitpaginated-comments.php:1222
actionadmin_menupaginated-comments.php:1223
actiontemplate_redirectpaginated-comments.php:1224
actionwp_headpaginated-comments.php:1225
filtercomment_post_redirectpaginated-comments.php:1226
Maintenance & Trust

Paginated Comments Maintenance & Trust

Maintenance Signals

WordPress version tested2.8.3
Last updatedUnknown
PHP min version
Downloads19K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Paginated Comments Developer Profile

spiderbiteman

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Paginated Comments

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/paginated-comments/js/paginated-comments.js/wp-content/plugins/paginated-comments/css/paginated-comments.css
Script Paths
/wp-content/plugins/paginated-comments/js/paginated-comments.js
Version Parameters
paginated-comments/js/paginated-comments.js?ver=paginated-comments/css/paginated-comments.css?ver=

HTML / DOM Fingerprints

CSS Classes
comment-paginationcomment-pagination-linkscomment-pagination-nextcomment-pagination-prevcomment-pagination-firstcomment-pagination-lastcomment-pagination-numbercomment-pagination-page+2 more
HTML Comments
<!-- paginated-comments begin<!-- paginated-comments end
Data Attributes
data-paged-comments-pagedata-paged-comments-post-iddata-paged-comments-total-pages
JS Globals
window.paginatedComments
FAQ

Frequently Asked Questions about Paginated Comments