
CM Footnotes – Boost your content’s credibility with footnotes, citations, and bibliography Security & Risk Analysis
wordpress.org/plugins/cm-footnotesAdd and manage footnotes, citations, and bibliography with this footnotes Plugin. Improve clarity and provide references.
Is CM Footnotes – Boost your content’s credibility with footnotes, citations, and bibliography Safe to Use in 2026?
Generally Safe
Score 100/100CM Footnotes – Boost your content’s credibility with footnotes, citations, and bibliography has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cm-footnotes" v2.2.2 plugin exhibits a mixed security posture. On the positive side, it demonstrates strong practices regarding SQL query handling by exclusively using prepared statements and shows a commitment to security by implementing nonce checks for all identified AJAX handlers. The absence of known CVEs and historical vulnerabilities suggests a developer who has historically prioritized security. However, the static analysis reveals areas of concern that warrant attention.
Specifically, the presence of 3 AJAX handlers without authentication checks represents a significant attack surface. While the taint analysis found no critical or high severity issues, there was one flow with unsanitized paths, which could potentially lead to vulnerabilities if exploited in conjunction with other weaknesses. Furthermore, the relatively low percentage of properly escaped output (40%) indicates a potential risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data might not be adequately neutralized before being displayed.
In conclusion, while the plugin benefits from secure SQL practices and a clean vulnerability history, the unprotected AJAX endpoints and the significant number of unescaped outputs introduce notable security risks. These factors, combined with the unsanitized path flow, mean that despite a good historical record, the current version requires careful consideration and potential remediation to fully secure its attack surface.
Key Concerns
- Unprotected AJAX handlers
- Significant unescaped output
- Unsanitized path flow
CM Footnotes – Boost your content’s credibility with footnotes, citations, and bibliography Security Vulnerabilities
CM Footnotes – Boost your content’s credibility with footnotes, citations, and bibliography Release Timeline
CM Footnotes – Boost your content’s credibility with footnotes, citations, and bibliography Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
CM Footnotes – Boost your content’s credibility with footnotes, citations, and bibliography Attack Surface
AJAX Handlers 5
Shortcodes 4
WordPress Hooks 34
Maintenance & Trust
CM Footnotes – Boost your content’s credibility with footnotes, citations, and bibliography Maintenance & Trust
Maintenance Signals
Community Trust
CM Footnotes – Boost your content’s credibility with footnotes, citations, and bibliography Alternatives
Endnotes
endnotes
Easily add footnotes to your posts and pages.
CiteKit – Citation and Reference Manager
citation-reference-manager
Add citations, footnotes, tooltips, and bibliographies to your WordPress content. Manage all your references in one place and generate automatic APA, …
Footnotes Made Easy
footnotes-made-easy
Allows post authors to easily add and manage footnotes in posts.
Simple Footnotes
simple-footnotes
Create simple, elegant footnotes on your site. Use the [ref] shortcode and the plugin takes care of the rest.
Better Footnotes
better-footnotes
A robust solution to provide a fast reference and link to additional information for your readers
CM Footnotes – Boost your content’s credibility with footnotes, citations, and bibliography Developer Profile
19 plugins · 22K total installs
How We Detect CM Footnotes – Boost your content’s credibility with footnotes, citations, and bibliography
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cm-footnotes/assets/css/font.css/wp-content/plugins/cm-footnotes/assets/css/style.css/wp-content/plugins/cm-footnotes/assets/js/editor.js/wp-content/plugins/cm-footnotes/assets/js/front.js/wp-content/plugins/cm-footnotes/assets/js/settings.js/wp-content/plugins/cm-footnotes/assets/js/editor.js/wp-content/plugins/cm-footnotes/assets/js/front.js/wp-content/plugins/cm-footnotes/assets/js/settings.js/wp-content/plugins/cm-footnotes/assets/css/font.css?ver=/wp-content/plugins/cm-footnotes/assets/css/style.css?ver=/wp-content/plugins/cm-footnotes/assets/js/editor.js?ver=/wp-content/plugins/cm-footnotes/assets/js/front.js?ver=/wp-content/plugins/cm-footnotes/assets/js/settings.js?ver=HTML / DOM Fingerprints
cmf-simple-footnotecmf-simple-footnote-definitionscmf-simple-footnote-labeldata-cmf-simple-footnote-idCMF_front[cm_simple_footnote]