
Site Notes: Feedback, Notes with Sitewide Visual Commenting Security & Risk Analysis
wordpress.org/plugins/analogwp-site-notesA comprehensive solution for agency-client transitions with visual commenting system, task management, and collaborative features.
Is Site Notes: Feedback, Notes with Sitewide Visual Commenting Safe to Use in 2026?
Generally Safe
Score 100/100Site Notes: Feedback, Notes with Sitewide Visual Commenting has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "analogwp-site-notes" plugin version 1.2.0 exhibits a generally strong security posture with several positive indicators. Notably, all identified AJAX handlers and REST API routes appear to be protected by authentication and permission checks, and there are no discovered shortcodes or cron events that could introduce vulnerabilities. The code also demonstrates excellent practices regarding output escaping, with 100% of outputs being properly escaped, and a high percentage (92%) of SQL queries utilizing prepared statements. The absence of known CVEs and past vulnerabilities is also a significant positive sign, suggesting a commitment to security by the developers.
However, the static analysis does reveal areas of concern that warrant attention. The presence of 4 "flows with unsanitized paths" and 3 "taint analysis" findings classified as high severity indicate potential weaknesses where user-supplied data might not be adequately validated or sanitized before being used in sensitive operations. While the specific nature of these unsanitized paths isn't detailed, they represent a non-trivial risk. Additionally, while the number of file operations is low, any interaction with the file system, especially when combined with unsanitized paths, can be a vector for attacks. The inclusion of the Freemius v1.0 library also raises a minor concern if it's an outdated version, as bundled libraries can introduce vulnerabilities if not kept up-to-date.
In conclusion, the plugin has a solid foundation with robust defenses against common web vulnerabilities like unescaped output and unprotected AJAX endpoints. The lack of historical vulnerabilities further bolsters confidence. Nevertheless, the identified high-severity taint flows and unsanitized paths are the primary security concerns that need thorough investigation and remediation to ensure the plugin's overall security. Addressing these specific code-level issues would significantly enhance the plugin's security profile.
Key Concerns
- High severity taint flows found
- Flows with unsanitized paths
- Bundled outdated library (Freemius v1.0)
Site Notes: Feedback, Notes with Sitewide Visual Commenting Security Vulnerabilities
Site Notes: Feedback, Notes with Sitewide Visual Commenting Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Site Notes: Feedback, Notes with Sitewide Visual Commenting Attack Surface
AJAX Handlers 16
WordPress Hooks 16
Maintenance & Trust
Site Notes: Feedback, Notes with Sitewide Visual Commenting Maintenance & Trust
Maintenance Signals
Community Trust
Site Notes: Feedback, Notes with Sitewide Visual Commenting Alternatives
Dan's Annotator
dans-annotator
Lightweight front-end annotation tool with threads, tagging, and collaborator sessions.
Collaborative Post Notes
collaborative-post-notes
A lightweight, threaded internal notes system for WordPress posts and pages. Perfect for editorial teams, content creators, and multi-author websites.
Decent Comments
decent-comments
Decent Comments shows what people say. A more engaging way to show comments.
Changeloger – Release Notes & Changelog Manager
changeloger
The all-in-one changelog, release notes, public roadmap, and user feedback plugin for WordPress. Beautiful visual designs out of the box.
Team Collaboration & Content Workflow Plugin for WordPress Editorial Teams – Multicollab
commenting-feature
This plugin serves the commenting feature like Google Docs within the Gutenberg Editor!
Site Notes: Feedback, Notes with Sitewide Visual Commenting Developer Profile
3 plugins · 10K total installs
How We Detect Site Notes: Feedback, Notes with Sitewide Visual Commenting
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/analogwp-site-notes/assets/css/admin-style.css/wp-content/plugins/analogwp-site-notes/assets/css/frontend-style.css/wp-content/plugins/analogwp-site-notes/assets/js/frontend-script.js/wp-content/plugins/analogwp-site-notes/assets/js/admin-script.js/wp-content/plugins/analogwp-site-notes/assets/js/frontend-script.js/wp-content/plugins/analogwp-site-notes/assets/js/admin-script.jsanalogwp-site-notes/assets/css/admin-style.css?ver=analogwp-site-notes/assets/css/frontend-style.css?ver=analogwp-site-notes/assets/js/frontend-script.js?ver=analogwp-site-notes/assets/js/admin-script.js?ver=HTML / DOM Fingerprints
agwp-sn-admin-wrapperdata-agwp-sn-admin-ajax-urlagwp_sn_ext