Comment management tools affect public submission paths, administration screens, feeds, APIs, and multisite policy. Disable Comments – Remove Comments & Stop Spam [Multi-Site Support] version 2.8.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64686, confirming that the review focused on settings access, request validation, comment-related endpoints, role-aware controls, and consistent enforcement across supported site contexts.

Name ofDisable Comments – Remove Comments & Stop Spam [Multi-Site Support]
Version2.8.0
Active installations1+ million
DescriptionDisables comments globally or for selected post types, supports multisite controls, and provides management through the dashboard, WP-CLI, REST API, and XML-RPC.
SecuritySuccessfully tested for:
SQL Injection (SQLi)
Cross-Site Scripting (XSS) – Stored and Reflected
Cross-Site Request Forgery (CSRF)
Authentication Vulnerabilities
Authentication Bypass Exploits
Privilege Escalation
Buffer Overflow
Denial-of-Service (DoS) vectors
Data Leakage Vulnerabilities
Insecure Dependency Usage
Remote Code Execution (RCE) Risks
Unauthorized File Access
Insufficient Injection Protection
Information Disclosure via Misconfigured Endpoints
CleanTalk CertificationProudly earned the “Plugin Security Certification” (PSC) from CleanTalk, indicating adherence to stringent security standards.
Additional InformationUse Disable Comments – Remove Comments & Stop Spam [Multi-Site Support] with confidence backed by the “Plugin Security Certification” (PSC). Confirm comment behavior across posts, pages, media, feeds, REST routes, XML-RPC, and multisite settings after each configuration change.
Plugin Security Certification by CleanTalk
Logo of the plugin

Join the community of developers who prioritize security. Highlight your plugin in the WordPress catalog.

PSC by Cleantalk

Key Features

Disable Comments – Remove Comments & Stop Spam [Multi-Site Support] lets administrators disable comments across an entire site or for selected content types. It also removes comment-related interface elements and supports multisite management, WP-CLI, REST API, and XML-RPC workflows. Because the plugin changes both public behavior and administrative visibility, its settings need to remain consistent across each supported access path.

Security Assurance

The CleanTalk Plugin Security Certification evaluation focused on authorization for settings changes, request integrity, role-aware exclusions, and consistent enforcement on public and administrative routes. The review also considered comment feeds, REST and XML-RPC behavior, multisite boundaries, output handling, and protection against unauthorized changes to site-wide comment policy.

The plugin has been successfully tested for:

✅ Information Leakage Vulnerabilities

✅ SQL Injection Vulnerabilities

✅ Cross-Site Scripting (XSS) Attacks

✅ Cross-Site Request Forgery (CSRF) Attacks

✅ Authentication and Authentication Bypass Vulnerabilities

✅ Privilege Escalation Vulnerabilities

✅ Buffer Overflow Vulnerabilities

✅ Denial-of-Service (DoS) Vulnerabilities

✅ Data Leakage Vulnerabilities

✅ Insecure Dependencies

✅ Code Execution Vulnerabilities

✅ File Unauthorized Access Vulnerabilities

✅ Insufficient Injection Protection

Conclusion

With PSC-2026-64686, Disable Comments – Remove Comments & Stop Spam [Multi-Site Support] version 2.8.0 demonstrates strong baseline security for comment restriction and spam reduction workflows. The certification addresses settings access, role-aware controls, public submission paths, API behavior, and multisite enforcement. Site owners should verify existing comments separately, limit configuration access, and retest comment behavior whenever themes, content types, or network settings change.

Note: The date and certification information may change over time. It is advisable to verify the latest details on the plugin developer’s website.

Plugin Security Certification (PSC-2026-64686): “Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]” – Version 2.8.0

Dmitrii I

Pentester with 5 years of hands-on experience securing WordPress and web applications, holding OSWE, OSEP, OSCP, and OSWP certifications. Author of 450 published CVEs, including 35 disclosed within the last month. Specializes in discovering and validating high-impact vulnerabilities in WordPress plugins/themes / Custom WEB applications and delivering actionable remediation guidance to harden production sites.

Visit Author's Website

See all posts by dmitrii-ignatyev

Leave a Reply

Your email address will not be published. Required fields are marked *