Russian Number Comments Security & Risk Analysis

wordpress.org/plugins/russian-number-comments

Плагин позволяет переименовать "комментарии" в "отзывы", "отклики", "ответы" и тому подобное (а также правильно склоняет слово "комментарии").

100 active installs v2.00 PHP 5.3+ WP 2.3+ Updated May 19, 2025
commentscomments_numbercomments_popup_link
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Russian Number Comments Safe to Use in 2026?

Generally Safe

Score 100/100

Russian Number Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The "russian-number-comments" plugin v2.00 exhibits a strong security posture in several key areas. The static analysis reveals no apparent attack surface through AJAX, REST API, shortcodes, or cron events, indicating a deliberate effort to minimize potential entry points for malicious actors. Furthermore, the plugin demonstrates good practice by exclusively using prepared statements for SQL queries and employing both nonce and capability checks, which are crucial for preventing cross-site request forgery and unauthorized access. The absence of known CVEs and vulnerability history further reinforces this positive outlook.

However, the static analysis does highlight a significant concern regarding output escaping. With only 31% of outputs properly escaped, there is a considerable risk of cross-site scripting (XSS) vulnerabilities. Any user-supplied data that is displayed on the frontend without adequate sanitization could be exploited to inject malicious scripts, leading to session hijacking, defacement, or other harmful actions. While the plugin's attack surface is small and its core functionalities appear secure, this widespread lack of output escaping represents a notable weakness that could be leveraged by attackers.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Russian Number Comments Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Russian Number Comments Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
5 escaped
Nonce Checks
2
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

31% escaped16 total outputs
Attack Surface

Russian Number Comments Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionplugins_loadedrussian-number-comments.php:34
actionactivate_russian-number-comments/russian-number-comments.phprussian-number-comments.php:70
actioninitrussian-number-comments.php:92
actionadmin_enqueue_scriptsrussian-number-comments.php:119
actionadmin_menurussian-number-comments.php:258
filtercomments_numberrussian-number-comments.php:278
Maintenance & Trust

Russian Number Comments Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 19, 2025
PHP min version5.3
Downloads5K

Community Trust

Rating84/100
Number of ratings6
Active installs100
Developer Profile

Russian Number Comments Developer Profile

Flector

15 plugins · 44K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
782 days
View full developer profile
Detection Fingerprints

How We Detect Russian Number Comments

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/russian-number-comments/inc/jquery.lettering.js/wp-content/plugins/russian-number-comments/inc/jquery.textillate.js/wp-content/plugins/russian-number-comments/inc/animate.min.css/wp-content/plugins/russian-number-comments/inc/rnc-script.js/wp-content/plugins/russian-number-comments/inc/rnc-css.css
Script Paths
/wp-content/plugins/russian-number-comments/inc/rnc-script.js
Version Parameters
russian-number-comments/inc/rnc-script.js?ver=russian-number-comments/inc/rnc-css.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Russian Number Comments