Top Commentators Widget Security & Risk Analysis

wordpress.org/plugins/top-commentators-widget

Adds a sidebar widget to show the top commentators in your WP site. Demo: http://demo.webgrrrl.net

200 active installs v1.7 PHP + WP 2.8+ Updated Dec 20, 2025
commentsgravatarseosidebarwidget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Top Commentators Widget Safe to Use in 2026?

Generally Safe

Score 100/100

Top Commentators Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The 'top-commentators-widget' v1.7 plugin exhibits several concerning security practices despite a clean vulnerability history. The static analysis reveals a complete lack of input validation and output sanitization. All identified SQL queries are performed without prepared statements, introducing a significant risk of SQL injection vulnerabilities. Furthermore, a substantial 87 output points are present with a 0% proper escaping rate, indicating a high probability of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce and capability checks on any potential entry points, coupled with no observed taint flows that would flag immediate critical issues, paints a picture of a plugin that, while historically unexploited, has critical flaws in its implementation that leave it vulnerable. The clean vulnerability history may be due to the plugin's obscurity or a lack of thorough security audits in the past. Despite the lack of known CVEs, the identified coding deficiencies represent a tangible security risk.

Key Concerns

  • SQL queries without prepared statements
  • All output points unescaped (high XSS risk)
  • No nonce checks on potential entry points
  • No capability checks on potential entry points
Vulnerabilities
None known

Top Commentators Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Top Commentators Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
87
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

0% escaped87 total outputs
Attack Surface

Top Commentators Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_inittop-commentators-widget.php:17
Maintenance & Trust

Top Commentators Widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedDec 20, 2025
PHP min version
Downloads156K

Community Trust

Rating100/100
Number of ratings2
Active installs200
Developer Profile

Top Commentators Widget Developer Profile

Lorna Timbah

1 plugin · 200 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Top Commentators Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/top-commentators-widget/top-commentators-widget.css/wp-content/plugins/top-commentators-widget/top-commentators-widget.js
Script Paths
/wp-content/plugins/top-commentators-widget/top-commentators-widget.js
Version Parameters
top-commentators-widget/top-commentators-widget.css?ver=top-commentators-widget/top-commentators-widget.js?ver=

HTML / DOM Fingerprints

CSS Classes
topcommtcwAwardtcwGravatar
FAQ

Frequently Asked Questions about Top Commentators Widget