
WP Comment Stats Security & Risk Analysis
wordpress.org/plugins/wp-comment-statsShows detailed stats of your WordPress comments based on original plugin 'Comment Stats' - https://wordpress.org/plugins/comment-stats/
Is WP Comment Stats Safe to Use in 2026?
Generally Safe
Score 85/100WP Comment Stats has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-comment-stats plugin, version 1.0.3, exhibits a mixed security posture. On one hand, it demonstrates good practices by having a very small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events that are exposed. Furthermore, there are no known past vulnerabilities or CVEs associated with this plugin, suggesting a history of responsible development. However, the static analysis reveals significant concerns within the code itself.
The most prominent issues lie in the handling of SQL queries and output escaping. A substantial 67% of SQL queries are not using prepared statements, posing a risk of SQL injection if user-supplied data is not meticulously handled elsewhere. Compounding this, only 4% of outputs are properly escaped, indicating a high probability of cross-site scripting (XSS) vulnerabilities. The taint analysis further supports these concerns, revealing one flow with an unsanitized path and a high severity taint, directly linking potentially dangerous input to sensitive operations without adequate sanitization.
Despite the lack of known external vulnerabilities, the internal code quality, particularly regarding SQL and output sanitization, presents a considerable risk. The absence of nonce checks on any entry points (which are zero in this case) and limited capability checks also mean that any discovered vulnerabilities could potentially be exploited without robust authorization mechanisms. The plugin's strengths are its minimal attack surface and clean vulnerability history, but these are overshadowed by significant risks in data handling practices within the code.
Key Concerns
- High percentage of SQL queries not using prepared statements
- Low percentage of outputs properly escaped
- High severity taint flow with unsanitized path
- No nonce checks on entry points
WP Comment Stats Security Vulnerabilities
WP Comment Stats Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Comment Stats Attack Surface
WordPress Hooks 6
Maintenance & Trust
WP Comment Stats Maintenance & Trust
Maintenance Signals
Community Trust
WP Comment Stats Alternatives
WP Year End Stats
wp-yearendstats
Displays fancy stats about your blog which you can include in your year end review posts.
Site Stats Dashboard
site-stats-dashboard
Simple dashboard that displays site statistics (post count, comment count, visit count) in the admin panel.
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Antispam Bee
antispam-bee
Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.
WP Comment Stats Developer Profile
1 plugin · 10 total installs
How We Detect WP Comment Stats
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-comment-stats/css/plugin.cssHTML / DOM Fingerprints
popular-link