Admin Notices Manager Security & Risk Analysis

wordpress.org/plugins/admin-notices-manager

Better manage admin notices & never miss important developer messages!

10K active installs v1.6.0 PHP 7.2+ WP 5.0+ Updated Dec 4, 2025
admin-noticesdashboard-noticeshide-admin-noticesmanage-admin-noticesnotices
99
A · Safe
CVEs total1
Unpatched0
Last CVEJun 3, 2024
Safety Verdict

Is Admin Notices Manager Safe to Use in 2026?

Generally Safe

Score 99/100

Admin Notices Manager has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Jun 3, 2024Updated 5mo ago
Risk Assessment

The static analysis of admin-notices-manager v1.6.0 reveals a strong adherence to several core WordPress security best practices. The plugin demonstrates excellent data handling by using prepared statements for all its SQL queries and shows a good effort in output escaping, with a majority of outputs properly escaped. The absence of dangerous functions, file operations, and external HTTP requests further strengthens its security posture. The very small attack surface, with zero entry points identified without authentication, is a significant positive indicator.

However, the complete lack of nonce and capability checks across all identified entry points (even if there are zero unprotected ones) is a notable concern. While the static analysis didn't find any specific vulnerabilities stemming from this, it represents a foundational security gap that could be exploited if new entry points were inadvertently introduced or if the 'unprotected' count was inaccurate. The vulnerability history, featuring a past medium-severity issue related to Missing Authorization, reinforces the importance of robust authorization checks. This historical pattern, coupled with the static absence of capability checks, suggests a potential recurring weakness in how the plugin handles user permissions.

In conclusion, admin-notices-manager v1.6.0 exhibits commendable practices in data handling and I/O, and its current attack surface is minimal and seemingly protected. Nonetheless, the absence of explicit nonce and capability checks is a critical area for improvement. The past medium-severity vulnerability further highlights the need for diligent and comprehensive authorization mechanisms to ensure a truly secure user experience.

Key Concerns

  • No nonce checks on any entry points
  • No capability checks on any entry points
  • Past medium severity vulnerability (Missing Authorization)
  • Output escaping not 100% proper
Vulnerabilities
1 published

Admin Notices Manager Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-1717medium · 4.3Missing Authorization

Admin Notices Manager <= 1.4.0 - Missing Authorization to Authenticated (Subscriber+) User Email Retrieval

Jun 3, 2024 Patched in 1.5.0 (14d)
Version History

Admin Notices Manager Release Timeline

v1.6.0Current
v1.5.0
v1.4.01 CVE
v1.3.11 CVE
v1.3.01 CVE
v1.2.01 CVE
v1.1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Admin Notices Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
2
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

71% escaped7 total outputs
Attack Surface

Admin Notices Manager Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Admin Notices Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 4, 2025
PHP min version7.2
Downloads53K

Community Trust

Rating98/100
Number of ratings21
Active installs10K
Developer Profile

Admin Notices Manager Developer Profile

Melapress

6 plugins · 417K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
540 days
View full developer profile
Detection Fingerprints

How We Detect Admin Notices Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/admin-notices-manager/assets/dist/js/pointer.js
Script Paths
/wp-content/plugins/admin-notices-manager/assets/dist/js/pointer.js
Version Parameters
admin-notices-manager/assets/dist/js/pointer.js?ver=1.6.0

HTML / DOM Fingerprints

HTML Comments
Copyright(c) 2025 Melapress (email : info@melapress.com)This program is free software; you can redistribute it and/or modifyit under the terms of the GNU General Public License, version 2, aspublished by the Free Software Foundation.+7 more
JS Globals
anm_pointer_i18n
FAQ

Frequently Asked Questions about Admin Notices Manager