wp comment validation Security & Risk Analysis

wordpress.org/plugins/wp-comment-validation

wp-comment-validation adds validation for wordpress default comment submission form.

60 active installs v0.2 PHP + WP 3.5+ Updated May 12, 2015
comments-validationwordpress-comment-validation-plugin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is wp comment validation Safe to Use in 2026?

Generally Safe

Score 85/100

wp comment validation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "wp-comment-validation" plugin version 0.2 exhibits a seemingly low risk profile based on the provided static analysis and vulnerability history. The absence of any identified attack surface (AJAX, REST API, shortcodes, cron events), dangerous functions, direct SQL queries, file operations, external HTTP requests, or bundled libraries is a strong positive indicator. Furthermore, the lack of any recorded vulnerabilities, past or present, suggests a mature and secure development history. However, a significant concern arises from the "Output escaping" signal, which indicates that 100% of the 8 identified outputs are not properly escaped. This lack of output sanitization presents a clear risk of Cross-Site Scripting (XSS) vulnerabilities, especially if the data being output originates from user input or untrusted sources. While other security controls like nonce and capability checks are also reported as absent, the immediate and evident risk lies in the unescaped output.

Key Concerns

  • All identified outputs are not properly escaped
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

wp comment validation Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

wp comment validation Release Timeline

v0.1
Code Analysis
Analyzed Mar 16, 2026

wp comment validation Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped8 total outputs
Attack Surface

wp comment validation Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionwp_enqueue_scriptswp-comment-validation.php:34
actionwp_enqueue_scriptswp-comment-validation.php:40
actionadmin_menuwp-comment-validation.php:46
actionadmin_initwp-comment-validation.php:52
actionwp_footerwp-comment-validation.php:142
Maintenance & Trust

wp comment validation Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedMay 12, 2015
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs60
Developer Profile

wp comment validation Developer Profile

Ajay Sharma

4 plugins · 250 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect wp comment validation

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-comment-validation/css/jquery.validate.css/wp-content/plugins/wp-comment-validation/js/jquery.validate.js

HTML / DOM Fingerprints

HTML Comments
<!--validation ends-->
FAQ

Frequently Asked Questions about wp comment validation