
WP UGC Comments Security & Risk Analysis
wordpress.org/plugins/wp-ugc-commentsAdds the "ugc" value to the rel attribute for all links in comments and the author URLs.
Is WP UGC Comments Safe to Use in 2026?
Generally Safe
Score 85/100WP UGC Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the wp-ugc-comments plugin v1.00 appears to have a very strong security posture. The static analysis reveals a complete absence of any identifiable attack vectors such as AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the code demonstrates excellent security practices, with no dangerous functions, all SQL queries using prepared statements, and all output being properly escaped. The lack of file operations and external HTTP requests also contributes positively to its security profile.
The vulnerability history reinforces this positive assessment, with no known CVEs associated with this plugin at any severity level. This indicates a history of secure development or a lack of prior discovery of vulnerabilities.
While the complete lack of entry points and the rigorous application of security best practices are significant strengths, it's worth noting that the absence of any tested flows in taint analysis could mean that the analysis was incomplete or that the plugin genuinely has no user-input-driven code paths. However, given the other metrics, the plugin seems exceptionally well-secured for its current version.
WP UGC Comments Security Vulnerabilities
WP UGC Comments Release Timeline
WP UGC Comments Code Analysis
WP UGC Comments Attack Surface
WordPress Hooks 2
Maintenance & Trust
WP UGC Comments Maintenance & Trust
Maintenance Signals
Community Trust
WP UGC Comments Alternatives
Remove Yoast SEO Comments
remove-yoast-seo-comments
Removes the Yoast SEO advertisement HTML comments from your front-end source code.
No External Links
mihdan-no-external-links
Convert external links into internal links, site wide or post/page specific. Add NoFollow, Click logging, and more...
AnyComment
anycomment
AnyComment is blazing-fast commenting plugin based on React for WordPress.
UGC Comments
ugc-comments
The plugin allows you to manage the values of the "rel" attribute in comment links ("ugc", "nofollow").
SEO Super Comments
seo-super-comments
SEO Super Comments turns your comments into new pages.
WP UGC Comments Developer Profile
4 plugins · 2K total installs
How We Detect WP UGC Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
wp-ugc-comments/wp-ugc-comments.php?ver=HTML / DOM Fingerprints
rel="nofollow ugc"