
TwoSides Security & Risk Analysis
wordpress.org/plugins/twosidesSplit comments into two types of commenting groups.
Is TwoSides Safe to Use in 2026?
Generally Safe
Score 85/100TwoSides has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "twosides" plugin v1.1.0 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, all SQL queries utilizing prepared statements, and a high percentage of properly escaped output are excellent indicators of secure coding practices. Furthermore, the presence of nonce and capability checks, coupled with zero external HTTP requests or file operations, significantly reduces the potential attack surface. The plugin also boasts a clean vulnerability history with no known CVEs, suggesting a history of stability and security awareness.
However, it's important to note that the analysis did not uncover any taint flows, which could imply either a lack of complex data handling or a limitation in the static analysis tool's ability to detect certain types of vulnerabilities. The sole entry point, a shortcode, is not explicitly stated as being protected by authentication checks in the 'Unprotected' count. While the total entry points are low, this specific shortcode's implementation should be thoroughly reviewed to ensure it doesn't introduce vulnerabilities if it handles user-supplied data without proper sanitization or capability checks.
In conclusion, "twosides" v1.1.0 appears to be a well-developed plugin from a security perspective, with a strong emphasis on preventing common vulnerabilities. The low number of entry points and the robust implementation of security features are commendable. The main area for vigilance would be the specific implementation of the single shortcode to confirm it's adequately secured against potential misuse.
Key Concerns
- Shortcode entry point without explicit auth check noted
TwoSides Security Vulnerabilities
TwoSides Release Timeline
TwoSides Code Analysis
Output Escaping
TwoSides Attack Surface
Shortcodes 1
WordPress Hooks 18
Maintenance & Trust
TwoSides Maintenance & Trust
Maintenance Signals
Community Trust
TwoSides Alternatives
TrustMate.io – WooCommerce integration
trustmate-io-integration-for-woocommerce
TrustMate - Reviews for your shop and products at you WooCommerce site. Generate valuable traffic and profit more than others!
Stars Rating
stars-rating
A complete review plugin — star ratings, photo uploads, likes & dislikes, and Google rich snippets, all from one place.
Comment Rating Stars
comment-rating-stars
A simple plugin for adding review and rating functionality to WordPress comments.
Multilingual Comments
multilingual-comments
Multilingual Comments is an add-on for WPML / WooCommerce. This plugin makes it possible via its own plugin settings, to show: comments on blog posts …
WidgetPack Review System
widgetpack-review-system
The WidgetPack Review System replaces default WordPress comments with social review service to get more reviews mean more traffic and more sales.
TwoSides Developer Profile
19 plugins · 2K total installs
How We Detect TwoSides
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/twosides/library/twosides-debate-css.css/wp-content/plugins/twosides/library/twosides-debate-admin-css.css/wp-content/plugins/twosides/library/twosides-debate-plugin.js/wp-content/plugins/twosides/library/twosides-debate-colors.js/wp-content/plugins/twosides/library/twosides-debate-plugin.js/wp-content/plugins/twosides/library/twosides-debate-colors.jstwosides-debate-css?ver=twosides-debate-admin-css?ver=twosides-debate-plugin?ver=twosides-debate-colors?ver=HTML / DOM Fingerprints
twosides-debate-comment<!-- @id F2 --><!-- @id F5 --><!-- @id A1 --><!-- @id A7 -->+12 moretwosides_commtypetwosides_debate_debug_class[twosides_form_header]