CBX Changelog & Release Note Security & Risk Analysis

wordpress.org/plugins/cbxchangelog

A complete changelog and release note manager for your digital products or releasable projects.

300 active installs v2.0.10 PHP 7.4+ WP 5.3+ Updated Nov 16, 2025
changeloghistoryproduct-logreleaseversion
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CBX Changelog & Release Note Safe to Use in 2026?

Generally Safe

Score 100/100

CBX Changelog & Release Note has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "cbxchangelog" v2.0.10 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by having no recorded vulnerabilities (CVEs), no file operations, no external HTTP requests, and a high percentage of properly escaped outputs. The presence of nonces and capability checks for its entry points is also a strong security indicator. However, a significant concern arises from the attack surface analysis, where 5 out of 6 total entry points, specifically all AJAX handlers, lack authentication checks. This creates a considerable risk, as any unauthenticated user could potentially interact with these handlers, leading to unintended actions or information disclosure if vulnerabilities exist within them. The taint analysis shows no critical or high severity flows, which is reassuring, but the absence of taint analysis flows is also noted as a potential limitation. The plugin's history of zero vulnerabilities is a positive sign, suggesting a generally secure development approach, but this must be weighed against the exposed attack surface.

In conclusion, while the plugin has strong foundations in secure coding practices like output escaping and the absence of common risky operations, the lack of authentication on a majority of its AJAX handlers is a significant weakness. This leaves it vulnerable to unauthorized access and potential exploitation by malicious actors. The history of no vulnerabilities is a positive attribute, but it does not negate the immediate risks posed by the exposed AJAX endpoints. Users should be aware of this potential exposure and consider implementing additional security measures if direct access to these AJAX functions is a concern.

Key Concerns

  • AJAX handlers without auth checks
  • Large attack surface without auth checks
Vulnerabilities
None known

CBX Changelog & Release Note Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

CBX Changelog & Release Note Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
3 prepared
Unescaped Output
52
365 escaped
Nonce Checks
6
Capability Checks
7
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

75% prepared4 total queries

Output Escaping

88% escaped417 total outputs
Attack Surface
5 unprotected

CBX Changelog & Release Note Attack Surface

Entry Points6
Unprotected5

AJAX Handlers 5

authwp_ajax_cbxchangelog_settings_reset_loadincludes\CBXChangelog.php:218
authwp_ajax_cbxchangelog_settings_resetincludes\CBXChangelog.php:219
authwp_ajax_cbxchangelog_release_deleteincludes\CBXChangelog.php:222
authwp_ajax_cbxchangelog_release_resyncincludes\CBXChangelog.php:223
authwp_ajax_cbxchangelog_delete_releasesincludes\CBXChangelog.php:224

Shortcodes 1

[cbxchangelog] includes\CBXChangelogPublic.php:85
WordPress Hooks 28
actionadmin_noticesincludes\CBXChangelog.php:89
actionadmin_initincludes\CBXChangelog.php:173
actioninitincludes\CBXChangelog.php:176
actionadmin_menuincludes\CBXChangelog.php:179
actionadd_meta_boxesincludes\CBXChangelog.php:182
actionsave_postincludes\CBXChangelog.php:186
filtermanage_edit-cbxchangelog_columnsincludes\CBXChangelog.php:189
actionmanage_cbxchangelog_posts_custom_columnincludes\CBXChangelog.php:190
actionadmin_enqueue_scriptsincludes\CBXChangelog.php:192
actionadmin_enqueue_scriptsincludes\CBXChangelog.php:193
filterplugin_row_metaincludes\CBXChangelog.php:197
actionadmin_headincludes\CBXChangelog.php:199
actionplugins_loadedincludes\CBXChangelog.php:202
actionadmin_noticesincludes\CBXChangelog.php:203
actionafter_plugin_row_cbxchangelogpro/cbxchangelogpro.phpincludes\CBXChangelog.php:204
filterblock_categories_allincludes\CBXChangelog.php:209
filterblock_categoriesincludes\CBXChangelog.php:211
actioninitincludes\CBXChangelog.php:214
actionactivated_pluginincludes\CBXChangelog.php:226
actioninitincludes\CBXChangelog.php:227
actioninitincludes\CBXChangelog.php:242
filterthe_contentincludes\CBXChangelog.php:243
actionwp_enqueue_scriptsincludes\CBXChangelog.php:246
actionwidgets_initincludes\CBXChangelog.php:251
actionelementor/widgets/widgets_registeredincludes\CBXChangelog.php:254
actionelementor/elements/categories_registeredincludes\CBXChangelog.php:257
actionelementor/editor/before_enqueue_scriptsincludes\CBXChangelog.php:259
filtermonths_dropdown_resultsincludes\CBXChangelogAdmin.php:887
Maintenance & Trust

CBX Changelog & Release Note Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 16, 2025
PHP min version7.4
Downloads12K

Community Trust

Rating100/100
Number of ratings3
Active installs300
Developer Profile

CBX Changelog & Release Note Developer Profile

Sabuj Kundu

9 plugins · 3K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
204 days
View full developer profile
Detection Fingerprints

How We Detect CBX Changelog & Release Note

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cbxchangelog/assets/css/admin.css/wp-content/plugins/cbxchangelog/assets/css/public.css/wp-content/plugins/cbxchangelog/assets/js/admin.js/wp-content/plugins/cbxchangelog/assets/js/public.js
Script Paths
/wp-content/plugins/cbxchangelog/assets/js/admin.js/wp-content/plugins/cbxchangelog/assets/js/public.js
Version Parameters
cbxchangelog/assets/css/admin.css?ver=cbxchangelog/assets/css/public.css?ver=cbxchangelog/assets/js/admin.js?ver=cbxchangelog/assets/js/public.js?ver=

HTML / DOM Fingerprints

CSS Classes
cbx-changelog
JS Globals
cbxchangelog_public_data
FAQ

Frequently Asked Questions about CBX Changelog & Release Note