
WP-CommentNavi Security & Risk Analysis
wordpress.org/plugins/wp-commentnaviAdds a more advanced paging navigation for your comments to your WordPress blog.
Is WP-CommentNavi Safe to Use in 2026?
Generally Safe
Score 85/100WP-CommentNavi has a strong security track record. Known vulnerabilities have been patched promptly.
The wp-commentnavi plugin version 1.12.2 exhibits a mixed security posture. On the positive side, the static analysis reveals no direct entry points into the plugin without authentication or proper permission checks, and all SQL queries are secured using prepared statements. This indicates a good understanding of fundamental WordPress security practices regarding database interactions and access control for core functionalities.
However, concerns arise from the output escaping. With 51 total outputs, only 51% are properly escaped. This leaves a significant portion of the plugin's output potentially vulnerable to Cross-Site Scripting (XSS) attacks, where malicious scripts could be injected into the user interface. While no active taint flows or dangerous functions were detected in this static analysis, the history of past vulnerabilities, specifically the 'Cross-site Scripting' type, reinforces the concern around improper output handling. The plugin has had at least one known CVE, suggesting a pattern where input validation or output sanitization might have been previously insufficient.
In conclusion, while the plugin has strengths in its lack of direct attack vectors and secure database queries, the prevalent issue with output escaping presents a notable risk. The past XSS vulnerability further emphasizes the need for meticulous attention to output sanitization. Addressing the unescaped outputs should be a priority to mitigate potential XSS risks.
Key Concerns
- Output escaping is not properly handled for 49% of outputs.
- Plugin has a history of known CVEs, indicating past vulnerabilities.
WP-CommentNavi Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP-CommentNavi <= 1.12.1 - Authenticated (Admin+) Stored Cross-Site Scripting
WP-CommentNavi Code Analysis
Output Escaping
WP-CommentNavi Attack Surface
WordPress Hooks 5
Maintenance & Trust
WP-CommentNavi Maintenance & Trust
Maintenance Signals
Community Trust
WP-CommentNavi Alternatives
WP-PageNavi
wp-pagenavi
Adds a more advanced paging navigation interface.
Page scroll to id
page-scroll-to-id
Create links that scroll the page smoothly to any id within the document.
Exclude Pages
exclude-pages
This plugin adds a checkbox, “include this page in menus”, uncheck this to exclude pages from the page navigation that users see on your site.
WP-Paginate
wp-paginate
WP-Paginate is a simple and flexible pagination plugin which provides users with better navigation on your WordPress site.
CC Child Pages
cc-child-pages
Display WordPress child pages in a responsive grid or list using a shortcode, Gutenberg block or Elementor widget.
WP-CommentNavi Developer Profile
20 plugins · 889K total installs
How We Detect WP-CommentNavi
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-commentnavi/commentnavi-css.cssHTML / DOM Fingerprints
wp-commentnaviwp-commentnavi-all-comments-linkclass="wp-commentnavi"class="wp-commentnavi-all-comments-link"class="pages"class="first"class="extend"class="current"+2 more<div class="wp-commentnavi"><a href="" class="wp-commentnavi-all-comments-link"<span class="pages">