Serious Toxic Comments Security & Risk Analysis

wordpress.org/plugins/serious-toxic-comments

Flag and block toxic comments from polluting your site with insults, threats, obscenities, etc.

0 active installs v1.1.1 PHP 5.6+ WP 4.3+ Updated Unknown
aicommentstensorflowtoxictoxicity
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Serious Toxic Comments Safe to Use in 2026?

Generally Safe

Score 100/100

Serious Toxic Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "serious-toxic-comments" plugin v1.1.1 demonstrates a strong adherence to several core WordPress security best practices. The absence of any identified SQL queries that are not prepared, zero file operations, and no external HTTP requests are significant strengths that reduce the attack surface. Furthermore, the lack of any reported CVEs in its history suggests a historically stable and secure plugin. This indicates a generally good security posture from the developers.

However, there are notable areas for concern that significantly impact its overall security. The static analysis reveals a concerningly low percentage (29%) of properly escaped output. This means a substantial portion of dynamic data generated by the plugin could be vulnerable to Cross-Site Scripting (XSS) attacks, especially if user-supplied data is not handled carefully before being outputted to the browser. Additionally, the complete lack of nonce checks and capability checks on any potential entry points (though zero are listed) raises a red flag. While the current entry point count is zero, if any are introduced in the future without proper authentication and authorization, the plugin would be immediately vulnerable.

In conclusion, while the plugin benefits from a clean vulnerability history and good practices in database interaction and external communication, the significant percentage of unescaped output and the absence of security checks on any potential entry points present a considerable risk. The developers have a solid foundation, but addressing the output escaping and ensuring future-proof security checks are implemented are critical for a truly secure plugin.

Key Concerns

  • Low output escaping percentage
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Serious Toxic Comments Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Serious Toxic Comments Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

29% escaped7 total outputs
Attack Surface

Serious Toxic Comments Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionwp_footerincludes\class-serious-toxic-comments-ext.php:18
actionplugins_loadedincludes\class-serious-toxic-comments.php:116
actionadmin_enqueue_scriptsincludes\class-serious-toxic-comments.php:127
actionadmin_enqueue_scriptsincludes\class-serious-toxic-comments.php:128
actionadmin_initincludes\class-serious-toxic-comments.php:131
actionwp_enqueue_scriptsincludes\class-serious-toxic-comments.php:144
actionwp_enqueue_scriptsincludes\class-serious-toxic-comments.php:145
Maintenance & Trust

Serious Toxic Comments Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedUnknown
PHP min version5.6
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Serious Toxic Comments Developer Profile

Jordi Cabot

3 plugins · 40 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Serious Toxic Comments

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/serious-toxic-comments/css/serious-toxic-comments-admin.css/wp-content/plugins/serious-toxic-comments/js/serious-toxic-comments-admin.js
Script Paths
/wp-content/plugins/serious-toxic-comments/js/serious-toxic-comments-admin.js
Version Parameters
serious-toxic-comments-admin.css?ver=serious-toxic-comments-admin.js?ver=

HTML / DOM Fingerprints

JS Globals
Serious_Toxic_Comments
FAQ

Frequently Asked Questions about Serious Toxic Comments