
Comments Extra Fields For Post,Pages and CPT Security & Risk Analysis
wordpress.org/plugins/wp-comment-fieldsThis plugin allow admin to add extra fields in comment area. These fields are saved as comment meta and is displayed under comment text.
Is Comments Extra Fields For Post,Pages and CPT Safe to Use in 2026?
Mostly Safe
Score 84/100Comments Extra Fields For Post,Pages and CPT is generally safe to use though it hasn't been updated recently. 3 past CVEs were resolved.
The "wp-comment-fields" plugin v5.1 presents a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL query handling, with 100% of queries utilizing prepared statements. The majority of output is also properly escaped (90%), and there are no reported critical or high-severity vulnerabilities, nor are there any currently unpatched CVEs. However, significant concerns arise from the attack surface. With 6 total entry points, 4 of which lack authentication checks, there is a substantial risk of unauthorized actions or information disclosure. This is further highlighted by the presence of 4 AJAX handlers without proper authorization checks, which are often prime targets for attackers. The vulnerability history, though currently free of unpatched issues, shows a pattern of medium-severity vulnerabilities including Cross-Site Request Forgery (CSRF), Missing Authorization, and Cross-site Scripting (XSS). The last reported vulnerability in February 2024 suggests ongoing security attention is needed. While the code signals generally look good, the high number of unprotected entry points and the past vulnerability types are the primary areas of concern, indicating a need for more robust authorization controls.
Key Concerns
- Unprotected AJAX handlers
- Missing authorization checks on entry points
- Past medium severity vulnerabilities (CSRF, Missing Auth, XSS)
- Bundled Select2 library
Comments Extra Fields For Post,Pages and CPT Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Comments Extra Fields For Post,Pages and CPT <= 5.0 - Cross-Site Request Forgery
Comments Extra Fields For Post,Pages and CPT <= 5.0 - Missing Authorization
WordPress Comments Fields <= 4.0 - Authenticated (Admin+) Stored Cross-Site Scripting
Comments Extra Fields For Post,Pages and CPT Release Timeline
Comments Extra Fields For Post,Pages and CPT Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Comments Extra Fields For Post,Pages and CPT Attack Surface
AJAX Handlers 6
WordPress Hooks 11
Maintenance & Trust
Comments Extra Fields For Post,Pages and CPT Maintenance & Trust
Maintenance Signals
Community Trust
Comments Extra Fields For Post,Pages and CPT Alternatives
Comments – wpDiscuz
wpdiscuz
AJAX powered realtime comments. Designed to extend WordPress native comments. Custom comment forms/fields. Making comments has never been so awesome!
No CAPTCHA reCAPTCHA
no-captcha-recaptcha
Protect WordPress login, registration, comment and BuddyPress registration forms with Google's No CAPTCHA reCAPTCHA.
Advanced Comment Form
comment-form
Advanced Comment Form lets you customize plenty of things on the default comment forms in WordPress.
Comment Form Js Validation
comment-form-js-validation
This plugin use for wordpress comments form js validation.
Comments Form Star Rating Plugin for WordPress
comments-form-star-rating
Allow your customers to add star rattings in comment form.
Comments Extra Fields For Post,Pages and CPT Developer Profile
29 plugins · 5K total installs
How We Detect Comments Extra Fields For Post,Pages and CPT
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-comment-fields/js/admin/pre-load.js/wp-content/plugins/wp-comment-fields/css/bootstrap/bootstrap.min.css/wp-content/plugins/wp-comment-fields/css/font-awesome/css/font-awesome.min.css/wp-content/plugins/wp-comment-fields/css/sweetalert.css/wp-content/plugins/wp-comment-fields/js/sweetalert.js/wp-content/plugins/wp-comment-fields/css/select2.css/wp-content/plugins/wp-comment-fields/js/select2.js/wp-content/plugins/wp-comment-fields/css/codemirror-theme.css+4 more/wp-content/plugins/wp-comment-fields/js/admin/pre-load.js/wp-content/plugins/wp-comment-fields/js/sweetalert.js/wp-content/plugins/wp-comment-fields/js/select2.js/wp-content/plugins/wp-comment-fields/js/admin/jquery.tabletojson.min.js/wp-content/plugins/wp-comment-fields/js/wpcomment-tooltip.js/wp-content/plugins/wp-comment-fields/js/admin/wpcomment-admin.jswp-comment-fields/js/admin/pre-load.js?ver=wp-comment-fields/css/bootstrap/bootstrap.min.css?ver=wp-comment-fields/css/font-awesome/css/font-awesome.min.css?ver=wp-comment-fields/css/sweetalert.css?ver=wp-comment-fields/js/sweetalert.js?ver=wp-comment-fields/css/select2.css?ver=wp-comment-fields/js/select2.js?ver=wp-comment-fields/css/codemirror-theme.css?ver=wp-comment-fields/js/admin/jquery.tabletojson.min.js?ver=wp-comment-fields/js/wpcomment-tooltip.js?ver=wp-comment-fields/css/wpcomment-admin.css?ver=wp-comment-fields/js/admin/wpcomment-admin.js?ver=HTML / DOM Fingerprints
wpcomment-fields-wrapperwpcomment-modal-boxwpcomment-sliderwpcomment-field-wpcomment-modal-bodywpcomment-req-field-idwpcomment-close-checkerwpcomment-close-fields+1 morewpcomment_vars