
@Reply \w comment preview Security & Risk Analysis
wordpress.org/plugins/reply-w-comment-previewThis plugin allows you to add Twitter-like @reply links to comments, including a preview of the comment replied to. MASHUP of this: http://www.
Is @Reply \w comment preview Safe to Use in 2026?
Generally Safe
Score 85/100@Reply \w comment preview has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "reply-w-comment-preview" v0.0.41 reveals a generally good security posture with no identified dangerous functions, SQL injection risks (all queries use prepared statements), file operations, or external HTTP requests. The attack surface is also nil, with no AJAX handlers, REST API routes, shortcodes, or cron events detected. Furthermore, the vulnerability history is clean, with zero known CVEs and no recorded past vulnerabilities, suggesting a history of secure development or minimal scrutiny. However, a significant concern arises from the complete lack of output escaping, meaning all 14 identified output points are potentially vulnerable to cross-site scripting (XSS) attacks. Additionally, the absence of any nonce or capability checks, combined with the bundled outdated jQuery library (v1.2.6), presents further risks. While the plugin boasts a zero attack surface and no known vulnerabilities, the unescaped output and outdated library are critical weaknesses that need immediate attention to mitigate potential security breaches.
Key Concerns
- 100% of outputs are unescaped
- Bundled outdated jQuery v1.2.6
- No nonce checks detected
- No capability checks detected
@Reply \w comment preview Security Vulnerabilities
@Reply \w comment preview Code Analysis
Bundled Libraries
Output Escaping
@Reply \w comment preview Attack Surface
WordPress Hooks 5
Maintenance & Trust
@Reply \w comment preview Maintenance & Trust
Maintenance Signals
Community Trust
@Reply \w comment preview Alternatives
@ Reply
reply-to
This plugin allows you to add Twitter-like @reply links to comments.
@reply
at-reply
Automagically link Twitterish "@name:" replies in comments.
Comment Email Reply
comment-email-reply
Simply notifies comment-author via email if someone replies to his comment. Zero Configuration.
ARK HideCommentLinks
ark-hidecommentlinks
Плагин закрывает ссылки на сайты комментаторов и убирает replytocom.
Comments Not Replied To
comments-not-replied-to
Easily see which comments have not received a reply yet.
@Reply \w comment preview Developer Profile
2 plugins · 20 total installs
How We Detect @Reply \w comment preview
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.