Postmatic Social Commenting Security & Risk Analysis

wordpress.org/plugins/postmatic-social-commenting

A tiny, fast, and convenient way to let your readers comment using their social profiles.

50 active installs v1.1.1 PHP + WP 3.0+ Updated Mar 11, 2016
facebookoauthsocialsocial-logintwitter
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Postmatic Social Commenting Safe to Use in 2026?

Generally Safe

Score 85/100

Postmatic Social Commenting has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The 'postmatic-social-commenting' v1.1.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries, having no recorded historical vulnerabilities, and a relatively small attack surface. However, a significant concern arises from the presence of one AJAX handler that lacks authentication checks. This unprotected entry point is a critical security gap, as it could potentially be exploited by unauthenticated users.

The static analysis reveals that while most output is properly escaped, the taint analysis indicates three flows with unsanitized paths. Although these are not classified as critical or high severity, they still represent potential vulnerabilities that could lead to unexpected behavior or information leakage if exploited. The absence of capability checks on any entry points further compounds the risk associated with the unprotected AJAX handler, as it means no specific user roles are validated for access.

Given the lack of known CVEs and historical issues, the plugin appears to be actively maintained or has historically been secure. However, the identified unprotected AJAX handler and unsanitized paths, despite their current severity classification, warrant immediate attention. The plugin's strengths lie in its data handling (SQL, output escaping) and lack of historical issues, but these are overshadowed by the direct risk of an unprotected entry point.

Key Concerns

  • Unprotected AJAX handler
  • Taint flows with unsanitized paths
  • No capability checks on entry points
Vulnerabilities
None known

Postmatic Social Commenting Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Postmatic Social Commenting Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
45 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
9
Bundled Libraries
0

Output Escaping

83% escaped54 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

4 flows3 with unsanitized paths
render_plugin_page (functions\Postmatic_Social_Comments_Plugin.php:61)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Postmatic Social Commenting Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

noprivwp_ajax_pms-logoutfunctions\Postmatic_Social_Network_Authenticator.php:19
WordPress Hooks 15
actionadmin_menufunctions\Postmatic_Social_Comments_Plugin.php:42
actionadmin_enqueue_scriptsfunctions\Postmatic_Social_Comments_Plugin.php:43
actionadmin_enqueue_scriptsfunctions\Postmatic_Social_Comments_Plugin.php:44
actionwp_enqueue_scriptsfunctions\Postmatic_Social_Comments_Plugin.php:46
actionwp_enqueue_scriptsfunctions\Postmatic_Social_Comments_Plugin.php:47
filterwp_get_current_commenterfunctions\Postmatic_Social_Comments_Plugin.php:48
filtercomments_openfunctions\Postmatic_Social_Comments_Plugin.php:49
filtercomment_form_field_commentfunctions\Postmatic_Social_Comments_Plugin.php:50
actionpreprocess_commentfunctions\Postmatic_Social_Comments_Plugin.php:51
actionshutdownfunctions\Postmatic_Social_Comments_Session.php:29
actionwp_footerfunctions\Postmatic_Social_Network_Authenticator.php:20
actionplugins_loadedpostmatic-social.php:77
actionprompt/core_loadedpostmatic-social.php:78
filterpre_comment_author_emailpostmatic-social.php:133
actioncomment_form_after_fieldspostmatic-social.php:152
Maintenance & Trust

Postmatic Social Commenting Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedMar 11, 2016
PHP min version
Downloads10K

Community Trust

Rating86/100
Number of ratings3
Active installs50
Developer Profile

Postmatic Social Commenting Developer Profile

Postmatic

2 plugins · 70 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Postmatic Social Commenting

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/postmatic-social-commenting/css/style.css/wp-content/plugins/postmatic-social-commenting/js/script.js
Script Paths
/wp-content/plugins/postmatic-social-commenting/js/script.js
Version Parameters
postmatic-social-commenting/css/style.css?ver=postmatic-social-commenting/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
comment-form-pms-extrapms-optinpms-optin-form
Data Attributes
id="pms_comment_subscribe"name="prompt_comment_subscribe"id="pms-email"name="pms-email"
FAQ

Frequently Asked Questions about Postmatic Social Commenting