
ByTheWay Annotations for WordPress Security & Risk Analysis
wordpress.org/plugins/bythewayByTheWay is a WordPress plugin providing shortcodes for collapsable annotations.
Is ByTheWay Annotations for WordPress Safe to Use in 2026?
Generally Safe
Score 85/100ByTheWay Annotations for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bytheway" v1.0.1 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, no raw SQL queries, no file operations, no external HTTP requests, and no bundled libraries, all of which are good security practices. The absence of known vulnerabilities and CVEs in its history is also a strong indicator of a generally well-maintained codebase. However, significant concerns arise from the complete lack of output escaping and the absence of nonce and capability checks.
The lack of proper output escaping for all 21 identified outputs is a critical weakness. This opens the door to Cross-Site Scripting (XSS) vulnerabilities, where attackers could inject malicious scripts into the website through user-supplied data that is then displayed without sanitization. Furthermore, the absence of nonce and capability checks on any of its entry points (shortcodes in this case) means that any authenticated user, regardless of their role or permissions, could potentially trigger the functionality associated with these shortcodes. While the attack surface isn't overwhelmingly large, the unprotected nature of these entry points is a serious oversight.
In conclusion, while the plugin avoids common pitfalls like raw SQL and dangerous functions, the critical flaws in output escaping and the lack of authorization checks for its shortcodes represent substantial security risks that require immediate attention. The clean vulnerability history is a positive sign but does not mitigate the inherent risks present in the current code.
Key Concerns
- All outputs are unescaped
- No nonce checks on entry points
- No capability checks on entry points
ByTheWay Annotations for WordPress Security Vulnerabilities
ByTheWay Annotations for WordPress Code Analysis
Output Escaping
ByTheWay Annotations for WordPress Attack Surface
Shortcodes 3
WordPress Hooks 10
Maintenance & Trust
ByTheWay Annotations for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
ByTheWay Annotations for WordPress Alternatives
Side Matter
side-matter
Turns footnotes into sidenotes, magically aligning each note in the sidebar next to its corresponding reference in the text.
Simple Commenter – Website Feedback tool
simple-commenter
The website feedback tool your clients will actually use. Collect visual feedback directly on your site—no training required.
ILAnnotations
ilannotations
Annotate any text in a blog post and add a comment to it.
Image Annotations
image-annotations
Image Annotations plugin lets readers to leave annotations to the selected area of the image in comments.
Inline Context
inline-context
Add inline expandable notes or tooltips to provide context, definitions, and references without disrupting the reading flow.
ByTheWay Annotations for WordPress Developer Profile
1 plugin · 10 total installs
How We Detect ByTheWay Annotations for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bytheway/styles.cssHTML / DOM Fingerprints
btw-buttonbtw-button-collapsedbtw-button-expandedbtw-contentbtw-quietmodebtw-chattymodebtw-resetmodedata-labelcollapseddata-tooltipcollapseddata-labelexpandeddata-tooltipexpanded<span class="btw-button btw-button-collapsed" data-labelcollapsed="-" data-tooltipcollapsed="Collapse annotation">-</span><span class="btw-button btw-button-expanded" data-labelexpanded="+" data-tooltipexpanded="Expand annotation">+</span><div class="btw-content">