
BreathWP – Quick Admin Notes Security & Risk Analysis
wordpress.org/plugins/breathwp-quick-admin-notesAdd multiple note cards to your WordPress dashboard for quick reminders, to-dos, and team messages.
Is BreathWP – Quick Admin Notes Safe to Use in 2026?
Generally Safe
Score 100/100BreathWP – Quick Admin Notes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "breathwp-quick-admin-notes" v1.3.0 plugin demonstrates a generally good security posture based on the static analysis. All identified AJAX entry points include nonce checks and capability checks, which are crucial for preventing unauthorized access and actions. The absence of dangerous functions, file operations, and external HTTP requests, along with the complete use of prepared statements for SQL queries, significantly reduces the attack surface and potential for common vulnerabilities like SQL injection and remote code execution. The lack of any recorded vulnerabilities in its history further strengthens this positive assessment, suggesting a history of secure development practices.
However, a significant concern arises from the output escaping analysis, where 64% of the 22 total outputs are properly escaped. This means that approximately 8 of the plugin's outputs are not adequately sanitized. If user-supplied data is directly outputted without proper escaping, it creates a risk of Cross-Site Scripting (XSS) vulnerabilities. While there are no current CVEs or taint analysis issues, this partial unescaped output presents a latent risk that could be exploited if an attacker can influence the data being displayed. Therefore, while the plugin is strong in many areas, this weakness in output sanitization requires attention to achieve a truly robust security profile.
Key Concerns
- Partially unescaped output detected
BreathWP – Quick Admin Notes Security Vulnerabilities
BreathWP – Quick Admin Notes Release Timeline
BreathWP – Quick Admin Notes Code Analysis
Output Escaping
BreathWP – Quick Admin Notes Attack Surface
AJAX Handlers 4
WordPress Hooks 2
Maintenance & Trust
BreathWP – Quick Admin Notes Maintenance & Trust
Maintenance Signals
Community Trust
BreathWP – Quick Admin Notes Alternatives
Sticky Notes for WP Dashboard
wb-sticky-notes
Create sticky notes in your WP admin for reminders and to-dos. Restrict notes by user roles and disable them on specific pages.
WP Dashboard Notes
wp-dashboard-notes
Working with multiple persons on a website? Want to make notes? You can do just that with WP Dashboard Notes. Create beautiful notes with a nice user …
Noted!
noted
A simple, lightweight, and user-friendly note-taking system within the WordPress admin.
Dashboard Notes
dashboard-notes
Easily create notes/instructions in the WordPress admin using any widget you like!
LH Dashboard Notes
lh-dashboard-notes
Allows you to create and edit notes that appear on the admin dashboard
BreathWP – Quick Admin Notes Developer Profile
1 plugin · 0 total installs
How We Detect BreathWP – Quick Admin Notes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/breathwp-quick-admin-notes/qanmc-script.js/wp-content/plugins/breathwp-quick-admin-notes/qanmc-style.css/wp-content/plugins/breathwp-quick-admin-notes/qanmc-script.jsbreathwp-quick-admin-notes/qanmc-script.js?ver=1.1breathwp-quick-admin-notes/qanmc-style.css?ver=1.2HTML / DOM Fingerprints
qanmc-notes-containerqanmc-noteqanmc-todo-listqanmc-todo-itemqanmc-todo-checkboxqanmc-todo-textqanmc-delete-todo-itemqanmc-add-todo-item+8 moredata-iddata-typedata-idxdata-sharedqanmc_ajaxqanmc_nonceqanmc_get_users_for_sharing