WPML comment merging Security & Risk Analysis

wordpress.org/plugins/wpml-comment-merging

This plugin merges comments from all WPML translations of the posts and pages, so that they all are displayed on each other.

100 active installs v1.3 PHP + WP 2.7+ Updated Feb 7, 2011
commentsi18nmultilingualtranslationwpml
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPML comment merging Safe to Use in 2026?

Generally Safe

Score 85/100

WPML comment merging has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the wpml-comment-merging plugin version 1.3 appears to have a strong security posture. The code analysis reveals no dangerous functions, no raw SQL queries, and all outputs are properly escaped. Furthermore, there are no identified file operations or external HTTP requests, and crucially, no identified flows through taint analysis. The complete absence of entry points like AJAX handlers, REST API routes, shortcodes, or cron events significantly reduces the potential attack surface. The plugin also demonstrates good practice by not bundling external libraries, which can often introduce vulnerabilities if not kept up-to-date.

The vulnerability history further reinforces this positive assessment, showing zero known CVEs, either currently unpatched or historically. This suggests a well-maintained codebase that has not had significant security flaws reported. While the current data presents a very clean picture, the lack of identified nonce and capability checks on the (zero) entry points, and the zero taint flows analyzed, could be interpreted as areas where the analysis might have been limited in scope or the plugin's functionality is extremely minimal. However, given the absence of any actual entry points, these are not immediate concerns but rather points to consider if functionality were to be added in the future.

In conclusion, the wpml-comment-merging plugin v1.3 presents a very low-risk profile. The code is clean, secure coding practices are evident, and there's no history of vulnerabilities. The absence of any attack surface is a significant strength. The primary limitation of this analysis is the lack of detected entry points, which means certain types of security checks (like nonces and capability checks) weren't exercised. However, without any entry points to begin with, this does not constitute a current risk.

Vulnerabilities
None known

WPML comment merging Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WPML comment merging Release Timeline

v1.3Current
v1.2
v1.1
v1.0
Code Analysis
Analyzed Mar 16, 2026

WPML comment merging Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

WPML comment merging Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filtercomments_arraywpml-comment-merging.php:61
filterget_comments_numberwpml-comment-merging.php:62
Maintenance & Trust

WPML comment merging Maintenance & Trust

Maintenance Signals

WordPress version tested3.0.5
Last updatedFeb 7, 2011
PHP min version
Downloads6K

Community Trust

Rating50/100
Number of ratings2
Active installs100
Developer Profile

WPML comment merging Developer Profile

CodingFabian

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WPML comment merging

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WPML comment merging