pipDisqus – Lightweight Disqus Comments Security & Risk Analysis

wordpress.org/plugins/pipdisqus

A lightweight solution for adding Disqus to your WordPress blog.

300 active installs v1.7 PHP + WP 4.2+ Updated Dec 3, 2025
commentscomments-systemdisquspost
99
A · Safe
CVEs total1
Unpatched0
Last CVEMar 11, 2025
Safety Verdict

Is pipDisqus – Lightweight Disqus Comments Safe to Use in 2026?

Generally Safe

Score 99/100

pipDisqus – Lightweight Disqus Comments has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Mar 11, 2025Updated 4mo ago
Risk Assessment

The pipdisqus v1.7 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL queries not using prepared statements, or unescaped output suggests good coding practices for preventing common vulnerabilities. Furthermore, the lack of critical or high severity taint analysis flows indicates that data is likely being handled safely within the plugin. The plugin also has no external HTTP requests or file operations, which reduces its attack surface and potential for certain types of exploits.

However, a significant concern is the presence of one known Common Vulnerabilities and Exposures (CVE) in its history, even though it is currently patched. The vulnerability type being Cross-site Scripting (XSS) is a common and potentially severe threat. While the static analysis shows no immediate vulnerabilities in the current code, the past XSS issue warrants attention and suggests a need for ongoing vigilance and testing to ensure such issues do not reappear in future versions. The plugin's limited attack surface (zero entry points found) is a positive indicator, but the single past CVE tempers the overall assessment.

In conclusion, pipdisqus v1.7 has commendable strengths in its static analysis, demonstrating diligent efforts to avoid common pitfalls. The absence of immediate critical risks in the code is reassuring. Nevertheless, the documented history of a past XSS vulnerability is a notable weakness that should not be overlooked. This necessitates a cautious approach, emphasizing the importance of thorough testing and security reviews for any updates to maintain its security.

Key Concerns

  • One known CVE in history
Vulnerabilities
1

pipDisqus – Lightweight Disqus Comments Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-28908medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

pipDisqus <= 1.6 - Authenticated (Administrator+) Stored Cross-Site Scripting

Mar 11, 2025 Patched in 1.7 (353d)
Code Analysis
Analyzed Mar 16, 2026

pipDisqus – Lightweight Disqus Comments Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
11 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped11 total outputs
Attack Surface

pipDisqus – Lightweight Disqus Comments Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_noticespipdisqus.php:28
filtercomments_templatepipdisqus.php:43
actionwp_footerpipdisqus.php:69
filterfeed_links_show_comments_feedpipdisqus.php:73
actionwp_before_admin_bar_renderpipdisqus.php:86
actionadmin_menupipdisqus.php:98
actionadmin_bar_menupipdisqus.php:121
actionadmin_menupipdisqus.php:129
actionadmin_initpipdisqus.php:152
Maintenance & Trust

pipDisqus – Lightweight Disqus Comments Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 3, 2025
PHP min version
Downloads18K

Community Trust

Rating90/100
Number of ratings6
Active installs300
Developer Profile

pipDisqus – Lightweight Disqus Comments Developer Profile

pipdig

10 plugins · 80K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
353 days
View full developer profile
Detection Fingerprints

How We Detect pipDisqus – Lightweight Disqus Comments

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/pipdisqus/js/pipdisqus.js
Version Parameters
pipdisqus/style.css?ver=pipdisqus/js/pipdisqus.js?ver=

HTML / DOM Fingerprints

CSS Classes
pipdisqus-containerpipdisqus_admin_noticepipdig-mod-comments
HTML Comments
<!-- Disqus Comments Start --><!-- Disqus Comments End -->
Data Attributes
data-disqus-shortnamedata-disqus-identifierdata-disqus-urldata-disqus-title
JS Globals
pipdisqus_load_comments
FAQ

Frequently Asked Questions about pipDisqus – Lightweight Disqus Comments