
Admin Notes Security & Risk Analysis
wordpress.org/plugins/admin-noteCreate notes for admin, one can assign to certain members easily.
Is Admin Notes Safe to Use in 2026?
Use With Caution
Score 63/100Admin Notes has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'admin-note' plugin v1.1 exhibits a mixed security posture. While the static analysis indicates a minimal attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events without proper checks, significant concerns arise from the code's internal practices. The complete lack of prepared statements for all SQL queries, coupled with a 0% rate of proper output escaping, presents a substantial risk. The taint analysis revealing one flow with an unsanitized path and high severity further exacerbates these issues, suggesting potential for injection vulnerabilities.
The plugin's vulnerability history, despite only one known medium CVE, is concerning due to its recentness and the fact that it remains unpatched. This indicates a pattern of security oversights and a lack of prompt remediation. While the plugin does implement one capability check, the overall lack of nonces on any entry points (though none are explicitly listed as unprotected) and the widespread use of raw SQL are critical weaknesses that overshadow the minimal attack surface. Users should exercise extreme caution, as the internal code quality and unaddressed past vulnerabilities suggest a high likelihood of future security issues.
Key Concerns
- All SQL queries use raw statements
- No output escaping
- High severity unsanitized taint flow
- One unpatched medium CVE
- No nonce checks
Admin Notes Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Admin Notes <= 1.1 - Cross-Site Request Forgery
Admin Notes Release Timeline
Admin Notes Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Admin Notes Attack Surface
WordPress Hooks 2
Maintenance & Trust
Admin Notes Maintenance & Trust
Maintenance Signals
Community Trust
Admin Notes Alternatives
Sticky Notes for WP Dashboard
wb-sticky-notes
Create sticky notes in your WP admin for reminders and to-dos. Restrict notes by user roles and disable them on specific pages.
User Notes
user-notes
Keep private notes about each of your users that only Administrators can see.
Simple Admin Notes
simple-admin-notes
Adds a simple "Notes" section to the admin menu or posts
Product Admin Notes Simple
products-admin-notes-simple
Simple plugin to add an admin notes field to products, nothing complicated just gets the job done!
A Note Above – WP Dashboard Notes
a-note-above-wp-dashboard-notes
A WordPress Note taking system to live on your WP Admin dashboard.
Admin Notes Developer Profile
1 plugin · 10 total installs
How We Detect Admin Notes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/adminnote/note.css/wp-content/plugins/adminnote/jquery.validate.min.js/wp-content/plugins/adminnote/jquery.validate.min.jsadminnote/note.css?ver=adminnote/jquery.validate.min.js?ver=HTML / DOM Fingerprints
paginationnotenote_loadingdata-note_idjQuery