
Update Comments Count Security & Risk Analysis
wordpress.org/plugins/update-comments-countAn easy way to update post comments counters, even for large sites, using WordPress standar function.
Is Update Comments Count Safe to Use in 2026?
Generally Safe
Score 85/100Update Comments Count has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "update-comments-count" v1.0 plugin exhibits a generally good security posture based on the provided static analysis. The absence of an attack surface, dangerous functions, file operations, and external HTTP requests are positive indicators. The presence of nonce and capability checks, along with a high percentage of properly escaped output, suggests an awareness of basic WordPress security best practices.
However, a significant concern arises from the taint analysis, which identified one flow with an unsanitized path and of high severity. This, coupled with the fact that both SQL queries are not using prepared statements, presents a potential risk. While there's no known vulnerability history, the presence of an unsanitized flow and raw SQL queries indicates a vulnerability that could be exploited, especially if the plugin were to gain more entry points or interact with untrusted data in the future.
In conclusion, while the plugin demonstrates some strong security foundations, the high-severity unsanitized taint flow and the use of raw SQL queries are critical weaknesses that require immediate attention. The lack of historical vulnerabilities is positive but does not negate the risks identified in the current code analysis. Addressing these specific code-level issues is paramount for improving the plugin's overall security.
Key Concerns
- High severity unsanitized taint flow
- SQL queries without prepared statements
Update Comments Count Security Vulnerabilities
Update Comments Count Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Update Comments Count Attack Surface
WordPress Hooks 3
Maintenance & Trust
Update Comments Count Maintenance & Trust
Maintenance Signals
Community Trust
Update Comments Count Alternatives
Tako Movable Comments
tako-movable-comments
Move WordPress comments easily with Tako Movable Comments.
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Antispam Bee
antispam-bee
Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.
Spam protection, Honeypot, Anti-Spam by CleanTalk
cleantalk-spam-protect
Blocks spam comments, fake users, contact form spam and more. No impact on SEO. Privacy focused. CAPTCHA free, premium Antispam plugin.
Update Comments Count Developer Profile
8 plugins · 620 total installs
How We Detect Update Comments Count
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/update-comments-count/update-comments-count.jsHTML / DOM Fingerprints
be-ucc-inputbe-ucc-progress-wrapperbe-ucc-progressid="be-ucc-input"id="be-ucc-nonce"id="be-ucc-action"id="be-ucc-pack"id="be-ucc-count"id="be-ucc-progress-wrapper"+7 more