Zeno Report Comments Security & Risk Analysis

wordpress.org/plugins/zeno-report-comments

This plugin gives your visitors the possibility to report a comment as inappropriate. After a set threshold the comment is put into moderation.

200 active installs v2.3.2 PHP 7.0+ WP 4.1+ Updated Jan 10, 2026
crowd-controlflag-commentsreport-commentssafe-report-commentsspam-comment
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Zeno Report Comments Safe to Use in 2026?

Generally Safe

Score 100/100

Zeno Report Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The zeno-report-comments plugin, version 2.3.2, exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and a high percentage of properly escaped output are significant strengths. The plugin also demonstrates good security practices by implementing nonce and capability checks on its entry points. The lack of file operations and external HTTP requests further reduces its attack surface. The taint analysis shows no critical or high severity flows, indicating a low risk of sensitive data being mishandled.

While the plugin's code quality appears to be high with no known vulnerabilities in its history, the primary area for potential concern lies in the interpretation of the 'Unprotected' entry points. The report states 3 AJAX handlers with 0 unprotected. This is a very positive sign, suggesting all entry points are properly secured. However, any component that can be triggered by an unauthenticated user, even if it contains internal authorization checks, can still present a minor risk if those checks are flawed or if the entry point itself becomes a target for denial-of-service attacks. Nevertheless, based on the provided data, the overall risk associated with this plugin is very low. The absence of historical vulnerabilities further reinforces this assessment, suggesting consistent security diligence by the developers.

Vulnerabilities
None known

Zeno Report Comments Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Zeno Report Comments Release Timeline

v2.3.2Current
v2.3.1
v2.3.0
v2.2.0
v2.1.4
v2.1.3
v2.1.2
v2.1.1
v2.1.0
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v2.0.0
Code Analysis
Analyzed Mar 16, 2026

Zeno Report Comments Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
44 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped47 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<frontend-hooks> (frontend-hooks.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Zeno Report Comments Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_zeno_report_comments_moderate_commentadmin-hooks.php:319
authwp_ajax_zeno_report_comments_flag_commentfrontend-hooks.php:208
noprivwp_ajax_zeno_report_comments_flag_commentfrontend-hooks.php:209
WordPress Hooks 19
actionadmin_initadmin-hooks.php:19
actionadmin_initadmin-hooks.php:41
actionadmin_initadmin-hooks.php:65
filtermanage_edit-comments_columnsadmin-hooks.php:160
filtermanage_edit-comments_sortable_columnsadmin-hooks.php:161
actionmanage_comments_custom_columnadmin-hooks.php:207
filtermanage_edit-comments_columnsadmin-hooks.php:220
actionmanage_comments_custom_columnadmin-hooks.php:260
actionadmin_enqueue_scriptsadmin-hooks.php:283
actioncomment_unapproved_to_approvedadmin-hooks.php:345
actioninitfrontend-hooks.php:20
actionzeno_report_comments_mark_flaggedfrontend-hooks.php:61
actionzeno_report_comments_add_reportfrontend-hooks.php:102
actionwp_enqueue_scriptsfrontend-hooks.php:161
actioncomment_report_abuse_linkfrontend-hooks.php:285
filtercomment_reply_linkfrontend-hooks.php:452
filtercomment_textfrontend-hooks.php:495
actioninitgeneral-functions.php:17
actiontemplate_redirectgeneral-functions.php:227
Maintenance & Trust

Zeno Report Comments Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 10, 2026
PHP min version7.0
Downloads12K

Community Trust

Rating100/100
Number of ratings8
Active installs200
Developer Profile

Zeno Report Comments Developer Profile

Marcel Pol

19 plugins · 82K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
1119 days
View full developer profile
Detection Fingerprints

How We Detect Zeno Report Comments

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
zeno-report-comments/style.css?ver=zeno-report-comments/script.js?ver=

HTML / DOM Fingerprints

Data Attributes
zrcmnt_thresholdzrcmnt_admin_notificationzrcmnt_admin_notification_eachzrcmnt_spamcheckzrcmnt_ipblock_from_reporting
FAQ

Frequently Asked Questions about Zeno Report Comments