
Better Page Comments Security & Risk Analysis
wordpress.org/plugins/swiftninjapro-commentsComments that Strip away HTML, but allow basic fonts in another way. Also includes some basic spam control options.
Is Better Page Comments Safe to Use in 2026?
Generally Safe
Score 85/100Better Page Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'swiftninjapro-comments' v1.4.9 presents a generally good security posture based on the static analysis. The absence of an attack surface with any direct entry points like AJAX handlers, REST API routes, or shortcodes is a significant strength. Furthermore, the plugin demonstrates good practices by utilizing prepared statements for all its SQL queries and performing capability checks on its limited code paths. The low number of taint flows and the absence of critical or high severity issues in this analysis are also positive indicators.
However, there are areas of concern. The taint analysis revealed three flows with unsanitized paths, which, while not classified as critical or high, represent potential avenues for exploitation if an attacker can manipulate the input. Additionally, a notable weakness is the lack of nonce checks, which is a standard security measure in WordPress to prevent Cross-Site Request Forgery (CSRF) attacks, especially when interacting with backend functionality. The fact that 30% of output is not properly escaped also introduces a risk of Cross-Site Scripting (XSS) vulnerabilities.
The plugin's vulnerability history is clean, with no recorded CVEs. This suggests a history of responsible development or a lack of past exploitation. However, the absence of past vulnerabilities does not guarantee future security. The combination of unsanitized paths, lack of nonce checks, and unescaped output, despite a good history and other positive code signals, indicates that while the plugin is not actively vulnerable based on the current analysis, there are fundamental security practices that are not consistently applied, leaving room for potential issues.
Key Concerns
- Flows with unsanitized paths
- Output escaping not fully implemented
- Nonce checks missing
Better Page Comments Security Vulnerabilities
Better Page Comments Code Analysis
Output Escaping
Data Flow Analysis
Better Page Comments Attack Surface
WordPress Hooks 5
Maintenance & Trust
Better Page Comments Maintenance & Trust
Maintenance Signals
Community Trust
Better Page Comments Alternatives
WP Toggle Comments Form
wp-toggle-comments-form-fields
Toggle The Comments Form Fields On Wordpress Posts And Pages
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Antispam Bee
antispam-bee
Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
Comment Link Remove and Other Comment Tools
comment-link-remove
Remove Comment Author Link & Links from Comments, Unlink, Disable Comments, Delete All Pending Comments. AI Auto Comment Reply, Voice, Attachments
Better Page Comments Developer Profile
7 plugins · 710 total installs
How We Detect Better Page Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/swiftninjapro-comments/assets/script.js/wp-content/plugins/swiftninjapro-comments/assets/script.jsswiftninjapro-comments/assets/script.js?ver=HTML / DOM Fingerprints
commentPostButton