
Site Notes: Site Feedback, Site Notes with Sitewide Visual Commenting Security & Risk Analysis
wordpress.org/plugins/analogwp-site-notesSite Notes is a one-stop solution for agency-client transitions with visual commenting and task management. Site Notes helps get easy Site feedback.
Is Site Notes: Site Feedback, Site Notes with Sitewide Visual Commenting Safe to Use in 2026?
Generally Safe
Score 100/100Site Notes: Site Feedback, Site Notes with Sitewide Visual Commenting has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "analogwp-site-notes" plugin version 1.2.0 exhibits a generally strong security posture with several positive indicators. Notably, all identified AJAX handlers and REST API routes appear to be protected by authentication and permission checks, and there are no discovered shortcodes or cron events that could introduce vulnerabilities. The code also demonstrates excellent practices regarding output escaping, with 100% of outputs being properly escaped, and a high percentage (92%) of SQL queries utilizing prepared statements. The absence of known CVEs and past vulnerabilities is also a significant positive sign, suggesting a commitment to security by the developers.
However, the static analysis does reveal areas of concern that warrant attention. The presence of 4 "flows with unsanitized paths" and 3 "taint analysis" findings classified as high severity indicate potential weaknesses where user-supplied data might not be adequately validated or sanitized before being used in sensitive operations. While the specific nature of these unsanitized paths isn't detailed, they represent a non-trivial risk. Additionally, while the number of file operations is low, any interaction with the file system, especially when combined with unsanitized paths, can be a vector for attacks. The inclusion of the Freemius v1.0 library also raises a minor concern if it's an outdated version, as bundled libraries can introduce vulnerabilities if not kept up-to-date.
In conclusion, the plugin has a solid foundation with robust defenses against common web vulnerabilities like unescaped output and unprotected AJAX endpoints. The lack of historical vulnerabilities further bolsters confidence. Nevertheless, the identified high-severity taint flows and unsanitized paths are the primary security concerns that need thorough investigation and remediation to ensure the plugin's overall security. Addressing these specific code-level issues would significantly enhance the plugin's security profile.
Key Concerns
- High severity taint flows found
- Flows with unsanitized paths
- Bundled outdated library (Freemius v1.0)
Site Notes: Site Feedback, Site Notes with Sitewide Visual Commenting Security Vulnerabilities
Site Notes: Site Feedback, Site Notes with Sitewide Visual Commenting Release Timeline
Site Notes: Site Feedback, Site Notes with Sitewide Visual Commenting Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Site Notes: Site Feedback, Site Notes with Sitewide Visual Commenting Attack Surface
AJAX Handlers 16
WordPress Hooks 16
Maintenance & Trust
Site Notes: Site Feedback, Site Notes with Sitewide Visual Commenting Maintenance & Trust
Maintenance Signals
Community Trust
Site Notes: Site Feedback, Site Notes with Sitewide Visual Commenting Alternatives
UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds
userfeedback-lite
Ultimate user feedback plugin to ask questions, surveys, polls, from your website in seconds
FeedFocal
feedfocal
Collect user feedback with our easy to use survey tools! Create surveys in seconds.
Mopinion Feedback Form
mopinion-feedback-form
Easy add feedback buttons and feedback forms to your website with the Mopinion.com Wordpress Plugin. Easy install, fast user insights.
Exit Intent Visitors Feedback – Trigger Feedback Popup on Exit Intent
visitors-feedback
Capture valuable feedback from your website visitors before they leave from your website.
UseResponse Feedback Widget
useresponse-feedback-widget
Collect feedback within your WordPress website with an easy-to-use and customizable widget from UseResponse.
Site Notes: Site Feedback, Site Notes with Sitewide Visual Commenting Developer Profile
3 plugins · 10K total installs
How We Detect Site Notes: Site Feedback, Site Notes with Sitewide Visual Commenting
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/analogwp-site-notes/assets/css/admin-style.css/wp-content/plugins/analogwp-site-notes/assets/css/frontend-style.css/wp-content/plugins/analogwp-site-notes/assets/js/frontend-script.js/wp-content/plugins/analogwp-site-notes/assets/js/admin-script.js/wp-content/plugins/analogwp-site-notes/assets/js/frontend-script.js/wp-content/plugins/analogwp-site-notes/assets/js/admin-script.jsanalogwp-site-notes/assets/css/admin-style.css?ver=analogwp-site-notes/assets/css/frontend-style.css?ver=analogwp-site-notes/assets/js/frontend-script.js?ver=analogwp-site-notes/assets/js/admin-script.js?ver=HTML / DOM Fingerprints
agwp-sn-admin-wrapperdata-agwp-sn-admin-ajax-urlagwp_sn_ext