
BQ Musical Notes Security & Risk Analysis
wordpress.org/plugins/bq-musical-notesConverts musical notes that use 'b' for flat and '#' for sharp into professional looking notes. Provides a shortcode to insert cho …
Is BQ Musical Notes Safe to Use in 2026?
Generally Safe
Score 85/100BQ Musical Notes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The bq-musical-notes plugin version 2.2 presents a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities (CVEs), no dangerous functions, no file operations, no external HTTP requests, and all SQL queries utilize prepared statements. This suggests a developer who is aware of common pitfalls in these areas. However, a significant concern is the complete lack of output escaping for 23 identified output points. This creates a high risk of Cross-Site Scripting (XSS) vulnerabilities, as any user-supplied data displayed on the frontend could be manipulated to execute malicious scripts. Additionally, the absence of nonce checks and capability checks, while not directly flagged as vulnerabilities in the static analysis, leaves potential entry points (like the shortcode) vulnerable to unauthorized actions or data manipulation if they interact with sensitive backend logic or data. The zero taint analysis flows and zero unprotected entry points are positive indicators, but the unescaped output is a critical oversight that heavily outweighs these strengths. While the plugin's history of no vulnerabilities is reassuring, it doesn't negate the immediate and severe risk posed by the unescaped output.
Key Concerns
- Output escaping is not used for any output
- No nonce checks implemented
- No capability checks implemented
BQ Musical Notes Security Vulnerabilities
BQ Musical Notes Release Timeline
BQ Musical Notes Code Analysis
Output Escaping
BQ Musical Notes Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
BQ Musical Notes Maintenance & Trust
Maintenance Signals
Community Trust
BQ Musical Notes Alternatives
No alternatives data available yet.
BQ Musical Notes Developer Profile
2 plugins · 20 total installs
How We Detect BQ Musical Notes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bq-musical-notes/bqnotes.css/wp-content/plugins/bq-musical-notes/bqnotes.js/wp-content/plugins/bq-musical-notes/bqnotes.jsbq-musical-notes/bqnotes.css?ver=bq-musical-notes/bqnotes.js?ver=HTML / DOM Fingerprints
bqnotes-sharpbqnotes-flat<div class="bqnotes-chord">