
Footnotes & Content Security & Risk Analysis
wordpress.org/plugins/awesome-footnotesAllows post authors to easily add and manage footnotes in posts.
Is Footnotes & Content Safe to Use in 2026?
Generally Safe
Score 100/100Footnotes & Content has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "awesome-footnotes" plugin v3.9.3 presents a generally good security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a clean taint analysis report are positive indicators. Furthermore, the plugin demonstrates good practices with SQL queries exclusively using prepared statements and a significant portion of outputs being properly escaped. The limited attack surface is also a strength.
However, there are notable areas of concern that temper this positive assessment. The presence of the `unserialize` function, even if not directly exploitable in the current analysis, represents a potential risk, especially if the data it processes originates from an untrusted source. More critically, the complete lack of nonce checks and capability checks on any potential entry points is a significant oversight. While the current analysis shows zero entry points, this indicates a lack of fundamental security mechanisms that would be crucial if any new entry points were introduced or discovered in future versions.
In conclusion, while the plugin currently appears stable and free from known vulnerabilities, the reliance on a small attack surface for security, coupled with the dangerous `unserialize` function and the absence of nonces and capability checks, introduces a latent risk. The plugin's security is heavily dependent on its limited exposure; if that exposure were to increase, the lack of built-in protections could become a serious liability. Therefore, while its current state is not overtly dangerous, proactive implementation of nonce and capability checks would significantly enhance its resilience.
Key Concerns
- Dangerous function unserialize found
- No nonce checks found
- No capability checks found
- 100% output escaping not achieved
Footnotes & Content Security Vulnerabilities
Footnotes & Content Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Footnotes & Content Attack Surface
Maintenance & Trust
Footnotes & Content Maintenance & Trust
Maintenance Signals
Community Trust
Footnotes & Content Alternatives
Footnotes Made Easy
footnotes-made-easy
Allows post authors to easily add and manage footnotes in posts.
Blank Footnotes
blank-footnotes
Simple plugin to show footnotes using markdown notation.
Simple Footnotes
simple-footnotes
Create simple, elegant footnotes on your site. Use the [ref] shortcode and the plugin takes care of the rest.
CM Footnotes – Boost your content’s credibility with footnotes, citations, and bibliography
cm-footnotes
Add and manage footnotes, citations, and bibliography with this footnotes Plugin. Improve clarity and provide references.
Endnotes
endnotes
Easily add footnotes to your posts and pages.
Footnotes & Content Developer Profile
2 plugins · 140 total installs
How We Detect Footnotes & Content
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/awesome-footnotes/assets/css/admin-style.css/wp-content/plugins/awesome-footnotes/assets/css/style.css/wp-content/plugins/awesome-footnotes/assets/js/admin-script.js/wp-content/plugins/awesome-footnotes/assets/js/front-script.js/wp-content/plugins/awesome-footnotes/assets/js/admin-script.js/wp-content/plugins/awesome-footnotes/assets/js/front-script.jsawesome-footnotes/assets/css/admin-style.css?ver=awesome-footnotes/assets/css/style.css?ver=awesome-footnotes/assets/js/admin-script.js?ver=awesome-footnotes/assets/js/front-script.js?ver=HTML / DOM Fingerprints
awef-footnoteawef-refdata-awef-footnote-idawef_ajax_object[awef_footnotes][awef_footnote]