
Show All Comments Security & Risk Analysis
wordpress.org/plugins/show-all-comments-in-one-pageThis plugin displays all the comments received on your various posts in a single page with filter, enabling the readers to read all the comments in a …
Is Show All Comments Safe to Use in 2026?
Use With Caution
Score 62/100Show All Comments has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "show-all-comments-in-one-page" plugin version 7.0.1 presents a significant security risk. The static analysis reveals a concerning lack of input validation and authorization checks. Two AJAX handlers are exposed without any authentication, creating a direct attack vector. Furthermore, all three SQL queries are executed without prepared statements, leaving the plugin vulnerable to SQL injection attacks. The taint analysis also indicates flows with unsanitized paths, although no critical or high severity issues were found in this specific analysis. The plugin's vulnerability history is a major red flag, with two known CVEs, one of which remains unpatched. The prevalence of Cross-site Scripting vulnerabilities in its history suggests a pattern of insufficient output escaping and improper input neutralization.
Key Concerns
- Unpatched CVE
- AJAX handlers without auth checks
- Raw SQL queries without prepare
- Low percentage of properly escaped output
- Missing nonce checks on AJAX
- Missing capability checks
- Flows with unsanitized paths
Show All Comments Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Show All Comments <= 7.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
Show All Comments <= 7.0.0 - Reflected Cross-Site Scripting
Show All Comments Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Show All Comments Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Show All Comments Maintenance & Trust
Maintenance Signals
Community Trust
Show All Comments Alternatives
No alternatives data available yet.
Show All Comments Developer Profile
8 plugins · 820 total installs
How We Detect Show All Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/show-all-comments-in-one-page/style.css/wp-content/plugins/show-all-comments-in-one-page/js/bt_script.js/wp-content/plugins/show-all-comments-in-one-page/js/bt_script.jsshow-all-comments-in-one-page/style.css?ver=show-all-comments-in-one-page/js/bt_script.js?ver=HTML / DOM Fingerprints
name="bt_post_type[]"name="bt_pagination"name="bt_comments_per_page"name="bt_exclude_post"name="biztech_sac_avatar"name="biztech_show_date"+5 more