ASN(Admin Sticky Notes) Security & Risk Analysis

wordpress.org/plugins/admin-sticky-notes

ASN(Admin Sticky Notes) is use for creating notes during your admin side work. it help you to remember pending works.

0 active installs v1.0.0 PHP + WP 4.9+ Updated Jan 9, 2018
adminnotesstickysticky-noteswordpress-plugin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is ASN(Admin Sticky Notes) Safe to Use in 2026?

Generally Safe

Score 85/100

ASN(Admin Sticky Notes) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "admin-sticky-notes" v1.0.0 plugin demonstrates a strong security posture based on the provided static analysis results. There are no identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the potential attack surface. The code also shows adherence to secure coding practices by not utilizing dangerous functions, all SQL queries being prepared, and all outputs being properly escaped. The absence of file operations, external HTTP requests, and the lack of bundled libraries further contribute to its secure design.

However, the analysis also reveals several areas of concern. The complete absence of nonce checks and capability checks across all potential interaction points is a significant weakness. This means that any functionality, if it were to be exposed (even though none are currently), would lack essential security measures to prevent unauthorized actions. The taint analysis showing zero flows, while seemingly positive, could be a result of the extremely limited attack surface rather than robust sanitization. The plugin also has no recorded vulnerability history, which is a positive indicator, but it's important to note that this is for a single, potentially new, version.

In conclusion, while the plugin's current design with its minimal attack surface and good coding practices is commendable, the complete lack of nonce and capability checks represents a critical oversight that could lead to severe vulnerabilities if any functionality is added or exposed in the future. This makes the plugin's current security highly dependent on its limited features rather than built-in defensive mechanisms.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

ASN(Admin Sticky Notes) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ASN(Admin Sticky Notes) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

ASN(Admin Sticky Notes) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_enqueue_scriptsadmin_notes.php:20
actionadmin_menuadmin_notes.php:22
actionadmin_menuadmin_notes.php:27
Maintenance & Trust

ASN(Admin Sticky Notes) Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJan 9, 2018
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

ASN(Admin Sticky Notes) Developer Profile

fgirach09

2 plugins · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ASN(Admin Sticky Notes)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/admin-sticky-notes/css/main.css/wp-content/plugins/admin-sticky-notes/js/interact.js/wp-content/plugins/admin-sticky-notes/js/custom.js
Script Paths
/wp-content/plugins/admin-sticky-notes/js/interact.js/wp-content/plugins/admin-sticky-notes/js/custom.js

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about ASN(Admin Sticky Notes)