
Admin Notebook Security & Risk Analysis
wordpress.org/plugins/admin-notebookNew Admin Notebook is simply allow wordpress site admin to add notes.
Is Admin Notebook Safe to Use in 2026?
Generally Safe
Score 85/100Admin Notebook has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The admin-notebook v2.1 plugin exhibits a concerning security posture primarily due to its unprotected entry points. While the plugin demonstrates good practices by avoiding dangerous functions, raw SQL queries, file operations, and external HTTP requests, the presence of two AJAX handlers without any authentication or capability checks represents a significant risk. This directly exposes functionalities to unauthorized users, potentially leading to unintended actions or information disclosure.
The taint analysis reveals two flows with unsanitized paths, which, while not flagged as critical or high severity, warrant attention. These flows, combined with the unprotected AJAX handlers, suggest a potential for attackers to manipulate input in ways that could lead to unexpected behavior or vulnerabilities, even if not immediately exploitable in a critical manner. The absence of any recorded vulnerability history might suggest a lack of past exploitation or discovery, but it does not mitigate the inherent risks present in the current codebase.
In conclusion, the admin-notebook plugin has some positive security attributes, but the critical flaw of unprotected AJAX handlers overshadows them. The lack of nonces and capability checks on these entry points makes it highly susceptible to unauthorized access and potential exploitation. This needs to be addressed immediately to improve the plugin's security.
Key Concerns
- AJAX handlers without auth checks
- Taint flows with unsanitized paths
- AJAX handlers without nonce checks
- Unprotected AJAX entry points
- 67% of outputs properly escaped
Admin Notebook Security Vulnerabilities
Admin Notebook Release Timeline
Admin Notebook Code Analysis
Output Escaping
Data Flow Analysis
Admin Notebook Attack Surface
AJAX Handlers 2
WordPress Hooks 4
Maintenance & Trust
Admin Notebook Maintenance & Trust
Maintenance Signals
Community Trust
Admin Notebook Alternatives
Sticky Notes for WP Dashboard
wb-sticky-notes
Create sticky notes in your WP admin for reminders and to-dos. Restrict notes by user roles and disable them on specific pages.
Quick Web Notes
quick-web-notes
Create and manage notes easily from both frontend and backend. Perfect for quick reminders, tasks, and ideas with drag-and-drop positioning.
Ultimate Sticky Notes
ultimate-sticky-notes
The Ultimate Sticky Notes plugin offers the create, organize, and customize notes on your admin panel.
Dashboard Sticky Notes
dashboard-sticky-notes
This plugin adds the functionality to add sticky notes into the dashboard.
Custom Sticky Notes
custom-sticky-notes
Add simple sticky notes in the WordPress admin bar.
Admin Notebook Developer Profile
2 plugins · 0 total installs
How We Detect Admin Notebook
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/admin-notebook/css/notebook_style.css/wp-content/plugins/admin-notebook/js/notebook_script.js/wp-content/plugins/admin-notebook/js/notebook_script.jsadmin-notebook/js/notebook_script.js?ver=1.0HTML / DOM Fingerprints
notebook_entryid="notebook"id="notebookheader"id="notebook_entry"name="notebook_entry"id="notebook_entry"class="notebook_entry"script_url/wp-json/admin-notebook