
Realtime Comments Security & Risk Analysis
wordpress.org/plugins/realtime-commentsAccepted comments from users are added to pages in real-time, without need to refresh. Makes comments section work interactively, like a chatroom.
Is Realtime Comments Safe to Use in 2026?
Generally Safe
Score 85/100Realtime Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The realtime-comments plugin v0.8 exhibits a mixed security posture. On the positive side, the static analysis reveals no critical or high severity taint flows, a clean vulnerability history with no recorded CVEs, and no apparent file operations or external HTTP requests. This suggests a generally well-contained plugin. However, significant concerns arise from the code signals. The low percentage of SQL queries using prepared statements (33%) and the even lower percentage of properly escaped output (10%) represent substantial risks. Without proper sanitization and escaping, the plugin is vulnerable to SQL injection and cross-site scripting (XSS) attacks, respectively, especially if data originating from user input is involved in these operations. The absence of nonce checks and capability checks on any entry points (though none were identified) could also be a latent risk if new entry points are introduced in future versions without adequate security. The vulnerability history, while currently clean, doesn't guarantee future safety, and the identified code weaknesses could easily lead to new vulnerabilities.
Key Concerns
- Low percentage of SQL prepared statements
- Very low percentage of output escaping
- No nonce checks on entry points
- No capability checks on entry points
Realtime Comments Security Vulnerabilities
Realtime Comments Code Analysis
SQL Query Safety
Output Escaping
Realtime Comments Attack Surface
WordPress Hooks 12
Maintenance & Trust
Realtime Comments Maintenance & Trust
Maintenance Signals
Community Trust
Realtime Comments Alternatives
WP Mercure
wp-mercure
Add WordPress integration of Mercure protocol and add realtime post modification.
heatmap for WordPress – Realtime analytics
heatmap-for-wp
Real-time analytics and event tracking for your WordPress sites.
Tako Movable Comments
tako-movable-comments
Move WordPress comments easily with Tako Movable Comments.
Update Comments Count
update-comments-count
An easy way to update post comments counters, even for large sites, using WordPress standar function.
Muut – Commenting and Forums Re-Imagined
muut
Muut represents a complete re-imagination of what internet discussion forums and commenting should be. It’s a modern, fast, highly scalable discussion …
Realtime Comments Developer Profile
1 plugin · 10 total installs
How We Detect Realtime Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/realtime-comments/css/rtc-admin.css/wp-content/plugins/realtime-comments/js/rtc-admin.js/wp-content/plugins/realtime-comments/js/rtc-client.js/wp-content/plugins/realtime-comments/js/rtc-client.jsrealtime-comments/css/rtc-admin.css?ver=realtime-comments/js/rtc-admin.js?ver=realtime-comments/js/rtc-client.js?ver=HTML / DOM Fingerprints
comment-listchildren<!-- realtime comments --><!-- /realtime comments -->data-comment-iddata-comment-statuswindow.rtc_settingsvar RTC_SETTINGS/wp-json/realtime-comments/v1/comments