CWE-1085 — Invokable Control Element with Excessive Volume of Commented-out Code
CWE-1085: Invokable Control Element with Excessive Volume of Commented-out Code
MITRE CWE weakness
| Kind | Weakness |
| Abstraction | Base |
| Status | Incomplete |
| Likelihood of exploit | — |
Description
A function, method, procedure, etc. contains an excessive amount of code that has been commented out within its body.
While the interpretation of "excessive volume" may vary for each product or developer, CISQ recommends a default threshold of 2% of commented code.
Common consequences
- Other: Reduce Maintainability
Mitigations
(none listed)
References
- CWE page: https://cwe.mitre.org/data/definitions/1085.html
- CWE list: https://cwe.mitre.org/data/index.html