Santi Tech Disable Posts & Comments Security & Risk Analysis

wordpress.org/plugins/santi-tech-disable-posts-comments

Removes "Posts" and "Comments" from the WordPress admin, disables comments site-wide, and can disable the Gutenberg editor.

10 active installs v1.6 PHP 7.0+ WP 5.0+ Updated Unknown
disable-commentsdisable-gutenbergdisable-postsremove-commentsremove-posts
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Santi Tech Disable Posts & Comments Safe to Use in 2026?

Generally Safe

Score 100/100

Santi Tech Disable Posts & Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "santi-tech-disable-posts-comments" v1.6 plugin exhibits a generally good security posture with no identified vulnerabilities in its history and a clean taint analysis. The plugin demonstrates a responsible approach by avoiding dangerous functions, file operations, and external HTTP requests. Furthermore, all SQL queries are properly prepared, which is a significant strength. However, a notable concern arises from the complete lack of output escaping for all 7 identified outputs. This means that any data processed and displayed by the plugin could be susceptible to cross-site scripting (XSS) attacks if not properly sanitized before being passed to these outputs. While the plugin has capability checks, the absence of nonce checks for AJAX requests (although there are no AJAX handlers) and the lack of explicit permission callbacks for REST API routes (again, none identified) suggest potential areas for improvement if the plugin were to expand its functionality.

Key Concerns

  • All identified outputs lack proper escaping
Vulnerabilities
None known

Santi Tech Disable Posts & Comments Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Santi Tech Disable Posts & Comments Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
0 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped7 total outputs
Attack Surface

Santi Tech Disable Posts & Comments Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionadmin_menusanti-tech-disable-posts-comments.php:14
actionadmin_initsanti-tech-disable-posts-comments.php:41
actionadmin_menusanti-tech-disable-posts-comments.php:131
filtercomments_opensanti-tech-disable-posts-comments.php:142
filterpings_opensanti-tech-disable-posts-comments.php:147
actionadmin_bar_menusanti-tech-disable-posts-comments.php:152
actionwidgets_initsanti-tech-disable-posts-comments.php:159
actioninitsanti-tech-disable-posts-comments.php:166
filteruse_block_editor_for_post_typesanti-tech-disable-posts-comments.php:175
filterupload_mimessanti-tech-disable-posts-comments.php:181
filterwp_check_filetype_and_extsanti-tech-disable-posts-comments.php:201
Maintenance & Trust

Santi Tech Disable Posts & Comments Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.0
Downloads454

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Santi Tech Disable Posts & Comments Developer Profile

Santi

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Santi Tech Disable Posts & Comments

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wrap
FAQ

Frequently Asked Questions about Santi Tech Disable Posts & Comments