
Annotix – Drag, Annotate, Feedback Security & Risk Analysis
wordpress.org/plugins/annotix-website-feedbackAnnotate any page on the frontend with screenshots, comments, file attachments, threaded replies, and email notifications.
Is Annotix – Drag, Annotate, Feedback Safe to Use in 2026?
Generally Safe
Score 100/100Annotix – Drag, Annotate, Feedback has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the 'annotix-website-feedback' plugin version 1.0.2 exhibits a concerning imbalance between good coding practices and potential attack vectors. On the positive side, the plugin demonstrates excellent data handling by exclusively using prepared statements for all SQL queries and ensuring all output is properly escaped. It also correctly utilizes nonces and capability checks in a significant portion of its code. However, a critical weakness lies in its attack surface. All seven REST API routes lack permission callbacks, meaning they are fully accessible without any authentication or authorization checks. This presents a significant risk as any user, including unauthenticated ones, can potentially interact with these endpoints. The static analysis found no critical or high-severity taint flows, and the plugin has no known vulnerability history, which are positive indicators. However, the absence of historical vulnerabilities should not lead to complacency, especially given the significant number of unprotected REST API entry points.
In conclusion, while the plugin employs sound practices for data handling and output sanitization, the extensive unprotected REST API endpoints represent a substantial security risk. The plugin is vulnerable to unauthorized access and manipulation of its REST API functionalities. Users of this plugin should be aware of this major flaw and ideally seek a version that addresses these access control issues. The lack of historical vulnerabilities is a strength, but it is heavily overshadowed by the immediate and exploitable attack surface.
Key Concerns
- REST API routes without permission callbacks
Annotix – Drag, Annotate, Feedback Security Vulnerabilities
Annotix – Drag, Annotate, Feedback Release Timeline
Annotix – Drag, Annotate, Feedback Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Annotix – Drag, Annotate, Feedback Attack Surface
REST API Routes 7
WordPress Hooks 14
Scheduled Events 1
Maintenance & Trust
Annotix – Drag, Annotate, Feedback Maintenance & Trust
Maintenance Signals
Community Trust
Annotix – Drag, Annotate, Feedback Alternatives
Dan's Annotator
dans-annotator
Lightweight front-end annotation tool with threads, tagging, and collaborator sessions.
Punchlist
punchlist
This plugin will allow you to share your posts and pages (including drafts!) for collaboration on Punchlist.
Atarim – Visual Feedback, Review & AI Collaboration
atarim-visual-collaboration
Make collecting feedback on WordPress sites MUCH faster and easier, with the visual collaboration tool used on over 120,000 websites worldwide.
Gleap
gleap
All-in-one customer feedback tool for websites. Learn more at https://www.gleap.io
Webvizio
webvizio
The Ultimate Visual Feedback, Collaboration & Productivity Tool for Web Professionals.
Annotix – Drag, Annotate, Feedback Developer Profile
1 plugin · 0 total installs
How We Detect Annotix – Drag, Annotate, Feedback
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/annotix-website-feedback/assets/css/frontend.css/wp-content/plugins/annotix-website-feedback/assets/js/html2canvas.min.js/wp-content/plugins/annotix-website-feedback/assets/js/frontend.jshttps://fonts.googleapis.com/css2?family=Inter:wght@400;500;600;700&family=Manrope:wght@600;700;800&display=swap/wp-content/plugins/annotix-website-feedback/assets/js/html2canvas.min.js/wp-content/plugins/annotix-website-feedback/assets/js/frontend.jsannotix-website-feedback/assets/css/frontend.cssannotix-website-feedback/assets/js/html2canvas.min.jsannotix-website-feedback/assets/js/frontend.jsHTML / DOM Fingerprints
antxData/wp-json/antx/v1/feedback/wp-json/antx/v1/feedback-pages