WP Webhooks – Comments Security & Risk Analysis

wordpress.org/plugins/wp-webhooks-comments

A WP Webhooks and WP Webhooks Pro extension for handling comments

10 active installs v1.1.0 PHP + WP 4.7+ Updated May 2, 2021
automationcommentsedit-commentironikuswebhooks
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Webhooks – Comments Safe to Use in 2026?

Generally Safe

Score 85/100

WP Webhooks – Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "wp-webhooks-comments" plugin v1.1.0 exhibits a seemingly strong security posture based on the provided static analysis, with zero identified attack surface points (AJAX, REST API, shortcodes, cron) and no detected dangerous functions or unescaped SQL queries. The lack of file operations and external HTTP requests further contributes to a reduced threat landscape. However, the significant concern lies in the absence of any capability checks or nonce checks across the entire codebase. While the current analysis shows no direct vulnerabilities, this pervasive lack of authorization and CSRF protection represents a substantial blind spot.

The vulnerability history is a blank slate, indicating no previously disclosed CVEs. This is generally a positive sign, but it could also mean the plugin hasn't been extensively scrutinized for vulnerabilities or that past versions did not possess exploitable flaws. The lack of any taint analysis results is also noted, which could imply either the absence of complex data flows or limitations in the analysis tool's capabilities for this specific plugin.

In conclusion, while the plugin avoids common pitfalls like insecure SQL or excessive attack vectors, the complete absence of security checks for authorization and CSRF is a critical weakness. This, combined with the unknown depth of taint analysis, means that despite a clean history, the plugin is not as secure as its superficial metrics might suggest and carries inherent risks due to the lack of fundamental security controls.

Key Concerns

  • No capability checks found
  • No nonce checks found
  • Low percentage of properly escaped output
Vulnerabilities
None known

WP Webhooks – Comments Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WP Webhooks – Comments Release Timeline

v1.1.0Current
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

WP Webhooks – Comments Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
36
16 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

31% escaped52 total outputs
Attack Surface

WP Webhooks – Comments Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
filterwpwhpro/webhooks/add_webhook_actionswp-webhooks-comments.php:27
actionwpwhpro/webhooks/add_webhooks_actionswp-webhooks-comments.php:29
filterwpwhpro/webhooks/get_webhooks_actionswp-webhooks-comments.php:31
actionplugins_loadedwp-webhooks-comments.php:34
filterwpwhpro/webhooks/get_webhooks_triggerswp-webhooks-comments.php:35
actionedit_commentwp-webhooks-comments.php:562
actionwp_insert_commentwp-webhooks-comments.php:566
actionwp_insert_commentwp-webhooks-comments.php:842
filterironikus_demo_test_create_commentwp-webhooks-comments.php:843
actionedit_commentwp-webhooks-comments.php:847
filterironikus_demo_test_update_commentwp-webhooks-comments.php:848
actiontrashed_commentwp-webhooks-comments.php:852
filterironikus_demo_test_trash_commentwp-webhooks-comments.php:853
actiondeleted_commentwp-webhooks-comments.php:857
filterironikus_demo_test_delete_commentwp-webhooks-comments.php:858
actionwpwhpro_plugin_loadedwp-webhooks-comments.php:1648
actionadmin_noticeswp-webhooks-comments.php:1652
Maintenance & Trust

WP Webhooks – Comments Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMay 2, 2021
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WP Webhooks – Comments Developer Profile

Cozmoslabs

11 plugins · 520K total installs

69
trust score
Avg Security Score
85/100
Avg Patch Time
613 days
View full developer profile
Detection Fingerprints

How We Detect WP Webhooks – Comments

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-webhooks-comments/wp-webhooks-comments.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WP Webhooks – Comments