
WP Comment Notes Security & Risk Analysis
wordpress.org/plugins/wp-comment-notesAdd custom notes before or after the comment form.
Is WP Comment Notes Safe to Use in 2026?
Generally Safe
Score 85/100WP Comment Notes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-comment-notes" plugin v1.0.0 presents a generally good security posture due to the absence of known vulnerabilities, critical taint flows, and the use of prepared statements for all SQL queries. The presence of nonce and capability checks is also a positive indicator of security awareness in its development. However, a significant concern arises from the low percentage of properly escaped output (28%). This suggests a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not consistently sanitized before being displayed to the user, even if the direct attack surface appears small. The lack of any recorded vulnerabilities in its history is a strong point, implying a history of secure development or a lack of targeted attacks. Overall, while the foundation is solid with secure coding practices for SQL and checks, the unescaped output represents a notable weakness that requires attention.
Key Concerns
- Low output escaping rate (28%)
WP Comment Notes Security Vulnerabilities
WP Comment Notes Code Analysis
Output Escaping
WP Comment Notes Attack Surface
WordPress Hooks 6
Maintenance & Trust
WP Comment Notes Maintenance & Trust
Maintenance Signals
Community Trust
WP Comment Notes Alternatives
Remove Comment Notes
remove-comment-notes
Removes the notes below the comment form.
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Antispam Bee
antispam-bee
Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.
Spam protection, Honeypot, Anti-Spam by CleanTalk
cleantalk-spam-protect
Blocks spam comments, fake users, contact form spam and more. No impact on SEO. Privacy focused. CAPTCHA free, premium Antispam plugin.
WP Comment Notes Developer Profile
18 plugins · 2K total installs
How We Detect WP Comment Notes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-comment-notes/lib/css/admin.csswpcmn-admin?ver=wp-comment-notes/lib/css/admin.css?ver=HTML / DOM Fingerprints
wpcmn-notes-tablewpcmn-notes-titlewpcmn-notes-datawpcmn-notes-before-textwpcmn-notes-before-typewpcmn-notes-after-textwpcmn-notes-after-typewpcmn-notes-standard+2 morename="wpcmn-notes[before-text]"id="wpcmn-before"name="wpcmn-notes[before-type]"id="wpcmn-before-type"name="wpcmn-notes[after-text]"id="wpcmn-after"+6 more