
Sz Comment Filter Security & Risk Analysis
wordpress.org/plugins/sz-comment-filterNo spam in comments. blocked by Invisible internal token-code with ajax.This is not used CAPTCHA.
Is Sz Comment Filter Safe to Use in 2026?
Generally Safe
Score 85/100Sz Comment Filter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sz-comment-filter" plugin version 1.1.2 exhibits significant security concerns, primarily stemming from its unprotected AJAX endpoints and the presence of dangerous functions. The analysis reveals two AJAX handlers, both lacking authentication checks, which presents a substantial attack surface. Furthermore, the `unserialize` function is used twice, indicating a potential for deserialization vulnerabilities if user-controlled data is passed to it without proper sanitization. While the plugin demonstrates good practices in using prepared statements for SQL queries and has no recorded vulnerability history, these strengths are overshadowed by the critical weaknesses in input validation and authentication.
The absence of any taint analysis findings and zero known CVEs are positive indicators, suggesting that in the past, the plugin may not have been a target or has been developed with some level of security awareness. However, the static analysis clearly points to areas where vulnerabilities could easily be introduced or exploited. The low percentage of properly escaped output also raises concerns about Cross-Site Scripting (XSS) vulnerabilities, although no direct taint flows were identified for this.
In conclusion, while the plugin has a clean vulnerability history and uses prepared statements, the lack of authentication on AJAX endpoints and the use of `unserialize` create a high-risk profile. These issues could lead to arbitrary code execution, unauthorized actions, or data manipulation. Recommendations for immediate action would include implementing robust authentication and authorization checks on all AJAX handlers and carefully sanitizing any data passed to the `unserialize` function.
Key Concerns
- AJAX handlers without authentication checks
- Use of unserialize function
- Low percentage of properly escaped output
- No nonce checks on AJAX handlers
- No capability checks on entry points
Sz Comment Filter Security Vulnerabilities
Sz Comment Filter Release Timeline
Sz Comment Filter Code Analysis
Dangerous Functions Found
Output Escaping
Sz Comment Filter Attack Surface
AJAX Handlers 2
WordPress Hooks 11
Maintenance & Trust
Sz Comment Filter Maintenance & Trust
Maintenance Signals
Community Trust
Sz Comment Filter Alternatives
Anti-spam Reloaded
anti-spam-reloaded
No spam in comments. No captcha.
Fortify
fortify
No spam in comments. No captcha.
Stop Media Comment Spamming
stop-media-comment-spamming
Stops media comment spamming by removing the ability to comment on attachments.
LH Zero Spam
lh-zero-spam
Zero Spam makes blocking spam comments and registrations easy.
Squelch Unspam
squelch-unspam
Unspam makes it harder for spammers to automatedly send spam to your blog by changing the names of the fields in the comment forms.
Sz Comment Filter Developer Profile
1 plugin · 10 total installs
How We Detect Sz Comment Filter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sz-comment-filter/css/styles-admin.css/wp-content/plugins/sz-comment-filter/js/scripts-admin.js/wp-content/plugins/sz-comment-filter/js/sz-comment-filter.js/wp-content/plugins/sz-comment-filter/js/sz-comment-filter.js/wp-content/plugins/sz-comment-filter/js/scripts-admin.jssz-comment-filter/js/sz-comment-filter.js?ver=sz-comment-filter/js/scripts-admin.js?ver=sz-comment-filter/css/styles-admin.css?ver=HTML / DOM Fingerprints
szmcf-inputszmcf-hunnypotname="szmcf-email-website-url"id="szmcf-email-website-url"class="szmcf-param"name="szmcf-key"id="szmcf-key"class="szmcf-param"+4 morevar szmcf_ajaxurl/wp-json/szmcf_currentkey