SG Autorepondeur Comment Security & Risk Analysis

wordpress.org/plugins/sg-autorepondeur-comment

A plugin which makes possible adding to your SG Autorepondeur Lists comment authors.

10 active installs v1.0.0 PHP + WP 3.0.1+ Updated Jul 29, 2019
autorespondercomment-opt-insg-autorepondeur
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SG Autorepondeur Comment Safe to Use in 2026?

Generally Safe

Score 85/100

SG Autorepondeur Comment has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The sg-autorepondeur-comment plugin v1.0.0 exhibits a mixed security posture. On the positive side, the static analysis reveals no identified dangerous functions, no raw SQL queries, and no file operations. Furthermore, there are no known vulnerabilities (CVEs) associated with this plugin, which is a significant strength. The absence of external HTTP requests and the fact that all identified SQL queries use prepared statements are also good indicators of secure coding practices.

However, there are notable areas of concern. The plugin has a low total number of output escaping instances (43), and a concerningly low percentage (30%) of these are properly escaped. This indicates a high likelihood of cross-site scripting (XSS) vulnerabilities where user-supplied data might be rendered without proper sanitization. Additionally, the complete absence of nonce checks and capability checks is a significant security gap. While the attack surface and entry points are reported as zero, this may be due to the static analysis not detecting any, but the lack of fundamental security mechanisms like nonces and capability checks on potential entry points (even if not explicitly found) leaves the plugin vulnerable to CSRF and unauthorized actions if any entry points are inadvertently exposed or introduced in future versions.

In conclusion, while the plugin benefits from a clean vulnerability history and sound database interaction practices, the insufficient output escaping and the complete lack of nonce and capability checks represent critical weaknesses. The potential for XSS vulnerabilities due to poor output sanitization is a substantial risk. Future development should prioritize addressing these issues and implementing robust security checks.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

SG Autorepondeur Comment Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

SG Autorepondeur Comment Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
30
13 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

30% escaped43 total outputs
Attack Surface

SG Autorepondeur Comment Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionplugins_loadedincludes\class-sg-autorepondeur-comment.php:143
actionadmin_initincludes\class-sg-autorepondeur-comment.php:159
actionadmin_menuincludes\class-sg-autorepondeur-comment.php:160
actionplugins_loadedincludes\class-sg-autorepondeur-comment.php:161
actionadmin_enqueue_scriptsincludes\class-sg-autorepondeur-comment.php:162
actionadmin_enqueue_scriptsincludes\class-sg-autorepondeur-comment.php:163
actioncomment_postincludes\class-sg-autorepondeur-comment.php:178
actioncomment_postincludes\class-sg-autorepondeur-comment.php:179
actioncomment_form_after_fieldsincludes\class-sg-autorepondeur-comment.php:180
actionwp_footerincludes\class-sg-autorepondeur-comment.php:181
actionwp_enqueue_scriptsincludes\class-sg-autorepondeur-comment.php:182
actionwp_enqueue_scriptsincludes\class-sg-autorepondeur-comment.php:183
Maintenance & Trust

SG Autorepondeur Comment Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedJul 29, 2019
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

SG Autorepondeur Comment Developer Profile

Lotfi MANSEUR

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SG Autorepondeur Comment

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sg-autorepondeur-comment/includes/sgarc_settings.php
Script Paths
/wp-content/plugins/sg-autorepondeur-comment/admin/js/sg-autorepondeur-comment-admin.js
Version Parameters
sg-autorepondeur-comment/admin/css/sg-autorepondeur-comment-admin.css?ver=sg-autorepondeur-comment/admin/js/sg-autorepondeur-comment-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
sgarc_settings_form
HTML Comments
<!-- Options de SG-Autorepondeur Comment -->
JS Globals
sgarc_settings_params
FAQ

Frequently Asked Questions about SG Autorepondeur Comment