
Private Comment Security & Risk Analysis
wordpress.org/plugins/private-commentAllow commenters to choose restrict their comments exhibition only to site owners
Is Private Comment Safe to Use in 2026?
Generally Safe
Score 99/100Private Comment has a strong security track record. Known vulnerabilities have been patched promptly.
The private-comment plugin v0.0.5 exhibits a generally positive security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points suggests a limited attack surface. The code also demonstrates good practices by exclusively using prepared statements for SQL queries and having a decent percentage of output correctly escaped. The lack of dangerous functions, file operations, and external HTTP requests further strengthens its security profile. However, the presence of one known, albeit patched, CVE related to Cross-site Scripting is a point of concern, indicating that past vulnerabilities have existed. While no critical taint flows were identified in the current analysis, the past XSS vulnerability highlights the potential for such issues if input handling is not meticulously maintained. Overall, the plugin appears to be developed with security in mind, but the historical vulnerability warrants continued vigilance.
Key Concerns
- Known vulnerability history (1 CVE)
- Output escaping is not 100% proper
- No nonce checks found
Private Comment Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Private Comment <= 0.0.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via Label Text Setting
Private Comment Code Analysis
Output Escaping
Private Comment Attack Surface
WordPress Hooks 12
Maintenance & Trust
Private Comment Maintenance & Trust
Maintenance Signals
Community Trust
Private Comment Alternatives
Better Messages – Live Chat, Chat Rooms, Real-Time Messaging & Private Messages
bp-better-messages
Real-time messaging and chat rooms for WordPress ecosystem: private conversations, public and private chat rooms, video & audio calls, and more.
Front End PM
front-end-pm
Front End PM is a Private Messaging system and a secure contact form to your WordPress site.This is full functioning messaging system from front end.
bbPress Messages
bbp-messages
bbPress Messages - Simple yet powerful private messaging system tailored for bbPress.
Front End PM – Ultimate Member Integration
front-end-pm-ultimate-member-integration
Front End PM extension to integrate with Ultimate Member
BuddyPress Messaging Control
bp-messaging-control
This plugin is a Swiss Army Knife for messaging, It allows the site admin to place restrictions on public and private messages including general rules …
Private Comment Developer Profile
6 plugins · 540 total installs
How We Detect Private Comment
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/private-comment/private-comment.phpHTML / DOM Fingerprints
comment-form-privateprivate-comment-display-privateid="wp-comment-private"