
WP Comments Remover Security & Risk Analysis
wordpress.org/plugins/wp-comments-removerA small plugin to remove pending comments using a search keyword.
Is WP Comments Remover Safe to Use in 2026?
Generally Safe
Score 85/100WP Comments Remover has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-comments-remover plugin v1.0.0.0 exhibits a mixed security posture. On the positive side, it demonstrates excellent practice by utilizing prepared statements for all SQL queries and avoids file operations and external HTTP requests. The absence of known CVEs and a clean vulnerability history are also strong indicators of responsible development. However, significant concerns arise from the static analysis of its code and taint flows. The complete lack of output escaping for all identified outputs is a critical weakness that could lead to cross-site scripting (XSS) vulnerabilities if any of the output data is user-controllable. Furthermore, the presence of two taint flows with unsanitized paths, even without critical or high severity designations, warrants attention as it suggests potential avenues for data manipulation or injection. The plugin also lacks nonce and capability checks, meaning its limited entry points, if they were to become exposed or gain functionality, would be entirely unprotected against unauthorized actions or data manipulation.
Key Concerns
- All outputs unescaped
- Unsanitized paths in taint flows
- No nonce checks
- No capability checks
WP Comments Remover Security Vulnerabilities
WP Comments Remover Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Comments Remover Attack Surface
WordPress Hooks 2
Maintenance & Trust
WP Comments Remover Maintenance & Trust
Maintenance Signals
Community Trust
WP Comments Remover Alternatives
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
WP Comment Cleaner – Delete All Comments, Disable Comments, Bulk Delete & Remove Comments
delete-all-comments-of-website
Delete comments, disable comments, and remove comments in one click. Bulk delete spam and all comments to optimize your WordPress database easily.
Delete Pending Comments
delete-pending-comments
A quick way to delete all pending and spam comments. Useful for victims of spammer attacks.
Disable Comments & Delete All Comments
comments-plus
Disable comments globally on all posts or certain post types. Delete all comments at once, by post type or comment status. Manage links in comments.
CRUDLab Disable Comments
crudlab-disable-comments
CRUDLab Disable Comments plugin allows you to disable comments for any page or post or for whole site.
WP Comments Remover Developer Profile
1 plugin · 30 total installs
How We Detect WP Comments Remover
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-comments-remover/css/wpcr.cssHTML / DOM Fingerprints
wrapsubmitexamplekwhideshowquestionlist