WP Spam Comments from BlashO Security & Risk Analysis

wordpress.org/plugins/wp-spam-comments

Automatically delete and clean all the spam comments from your blog. Just schedule it once.

10 active installs v1.4 PHP 5.2.4+ WP 3.0+ Updated Jan 15, 2018
adminblashocommentsspamspam-comments
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Spam Comments from BlashO Safe to Use in 2026?

Generally Safe

Score 85/100

WP Spam Comments from BlashO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The wp-spam-comments plugin version 1.4 presents a mixed security posture. On the positive side, it has no recorded vulnerabilities (CVEs), no critical or high severity taint flows, and doesn't utilize dangerous functions or make external HTTP requests. The absence of file operations and bundled libraries is also a good sign. However, there are significant areas of concern stemming from the static analysis. The presence of one unprotected AJAX handler is a critical security flaw, as it represents a direct entry point for potential attackers without any authentication or authorization checks. Furthermore, the low percentage of SQL queries using prepared statements (14%) and the very low percentage of properly escaped output (13%) indicate a high risk of SQL injection and cross-site scripting (XSS) vulnerabilities, respectively. The sole nonce check is insufficient given the attack surface. The vulnerability history being clear is a strength, suggesting the developers may be responsive to security issues, but this is overshadowed by the clear and present risks identified in the code analysis.

Key Concerns

  • Unprotected AJAX handler
  • Low SQL prepared statement usage
  • Low output escaping percentage
  • Missing capability checks
Vulnerabilities
None known

WP Spam Comments from BlashO Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Spam Comments from BlashO Code Analysis

Dangerous Functions
0
Raw SQL Queries
12
2 prepared
Unescaped Output
7
1 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

14% prepared14 total queries

Output Escaping

13% escaped8 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
WPSpamCommentsAdmin (wpspamcomments.php:112)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

WP Spam Comments from BlashO Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_my_actionwpspamcomments.php:14
WordPress Hooks 3
actionadmin_menuwpspamcomments.php:11
actionWPSpamCommentEventwpspamcomments.php:12
actionadmin_footerwpspamcomments.php:13

Scheduled Events 3

WPSpamCommentEvent
WPSpamCommentEvent
WPSpamCommentEvent
Maintenance & Trust

WP Spam Comments from BlashO Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJan 15, 2018
PHP min version5.2.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WP Spam Comments from BlashO Developer Profile

Ven Tesh

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Spam Comments from BlashO

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
modalcenter
Data Attributes
id="wpsc_loading"id="wpsc_updatedRow"id="cnt"
JS Globals
WPSpamComments_processajaxurl
REST Endpoints
/wp-json/
FAQ

Frequently Asked Questions about WP Spam Comments from BlashO