
Report Comments Security & Risk Analysis
wordpress.org/plugins/reportcommentsGives visitors the possibility to report inappropriate comments. Reported comments will show up in admin where they may be reviewed.
Is Report Comments Safe to Use in 2026?
Generally Safe
Score 85/100Report Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "reportcomments" plugin version 1.2 exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates good development practices by utilizing prepared statements for all SQL queries and implementing nonce and capability checks where appropriate. The absence of direct file operations, external HTTP requests, and known vulnerabilities further contributes to its positive security profile. However, a significant concern arises from the low percentage of properly escaped output. With only 5% of 21 identified output points being properly escaped, there is a substantial risk of cross-site scripting (XSS) vulnerabilities, particularly if user-supplied data is being rendered directly into the frontend without sufficient sanitization. While the vulnerability history is clean, the output escaping issue represents a significant potential weakness that could be exploited.
Key Concerns
- Low output escaping percentage
Report Comments Security Vulnerabilities
Report Comments Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Report Comments Attack Surface
WordPress Hooks 4
Maintenance & Trust
Report Comments Maintenance & Trust
Maintenance Signals
Community Trust
Report Comments Alternatives
MarcTV Moderate Comments
marctv-ajax-trash-comments
Grants visitors the ability to report inappropriate comments and admins to replace and trash them in the frontend.
Heartbeat Control
heartbeat-control
Allows you to easily manage the frequency of the WordPress heartbeat API.
Comments – wpDiscuz
wpdiscuz
AJAX powered realtime comments. Designed to extend WordPress native comments. Custom comment forms/fields. Making comments has never been so awesome!
AJAX Thumbnail Rebuild
ajax-thumbnail-rebuild
AJAX Thumbnail Rebuild allows you to rebuild all thumbnails at once without script timeouts on your server.
One Click Close Comments
one-click-close-comments
Conveniently close or open comments for a post or page with one click from the admin listing of posts.
Report Comments Developer Profile
1 plugin · 10 total installs
How We Detect Report Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/reportcomments/style.css/wp-content/plugins/reportcomments/reportcomments.js/wp-content/plugins/reportcomments/reportcomments.jsreportcomments/style.css?ver=reportcomments/reportcomments.js?ver=HTML / DOM Fingerprints
report-commentReportCommentsJs