CM Footnotes – Boost your content’s credibility with footnotes, citations, and bibliography Security & Risk Analysis

wordpress.org/plugins/cm-footnotes

Add and manage footnotes, citations, and bibliography with this footnotes Plugin. Improve clarity and provide references.

100 active installs v2.2.2 PHP 5.2.4+ WP 5.4.0+ Updated Jan 29, 2026
bibliographycitationsendnotesfootnotesreference
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CM Footnotes – Boost your content’s credibility with footnotes, citations, and bibliography Safe to Use in 2026?

Generally Safe

Score 100/100

CM Footnotes – Boost your content’s credibility with footnotes, citations, and bibliography has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "cm-footnotes" v2.2.2 plugin exhibits a mixed security posture. On the positive side, it demonstrates strong practices regarding SQL query handling by exclusively using prepared statements and shows a commitment to security by implementing nonce checks for all identified AJAX handlers. The absence of known CVEs and historical vulnerabilities suggests a developer who has historically prioritized security. However, the static analysis reveals areas of concern that warrant attention.

Specifically, the presence of 3 AJAX handlers without authentication checks represents a significant attack surface. While the taint analysis found no critical or high severity issues, there was one flow with unsanitized paths, which could potentially lead to vulnerabilities if exploited in conjunction with other weaknesses. Furthermore, the relatively low percentage of properly escaped output (40%) indicates a potential risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data might not be adequately neutralized before being displayed.

In conclusion, while the plugin benefits from secure SQL practices and a clean vulnerability history, the unprotected AJAX endpoints and the significant number of unescaped outputs introduce notable security risks. These factors, combined with the unsanitized path flow, mean that despite a good historical record, the current version requires careful consideration and potential remediation to fully secure its attack surface.

Key Concerns

  • Unprotected AJAX handlers
  • Significant unescaped output
  • Unsanitized path flow
Vulnerabilities
None known

CM Footnotes – Boost your content’s credibility with footnotes, citations, and bibliography Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

CM Footnotes – Boost your content’s credibility with footnotes, citations, and bibliography Release Timeline

v2.2.0
v2.1.10
v2.1.9
v2.1.8
v2.1.7
Code Analysis
Analyzed Mar 16, 2026

CM Footnotes – Boost your content’s credibility with footnotes, citations, and bibliography Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
214
142 escaped
Nonce Checks
5
Capability Checks
1
File Operations
0
External Requests
6
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

100% prepared4 total queries

Output Escaping

40% escaped356 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
cminds_system_info_content (package\cminds-free.php:2725)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

CM Footnotes – Boost your content’s credibility with footnotes, citations, and bibliography Attack Surface

Entry Points9
Unprotected3

AJAX Handlers 5

authwp_ajax_cm-submit-uninstall-reasonpackage\cminds-free.php:147
authwp_ajax_cm-submit-registration-emailpackage\cminds-free.php:148
authwp_ajax_cm-submit-deregistrationpackage\cminds-free.php:149
authwp_ajax_cm-submit-registration-skippackage\cminds-free.php:150
authwp_ajax_cmf_save_wizard_optionswizard.php:159

Shortcodes 4

[cminds_free_registration] package\cminds-free.php:54
[cminds_free_guide] package\cminds-free.php:55
[cminds_upgrade_box] package\cminds-free.php:56
[cminds_free_activation] package\cminds-free.php:57
WordPress Hooks 34
actionadmin_menuCMF_Free.php:47
actionadmin_initCMF_Free.php:48
actionwp_loadedCMF_Free.php:49
actionadmin_enqueue_scriptsCMF_Free.php:51
actionadmin_enqueue_scriptsCMF_Free.php:52
actionwp_print_stylesCMF_Free.php:54
actionadmin_noticesCMF_Free.php:55
actionadmin_noticesCMF_Free.php:56
actionwp_enqueue_scriptsCMF_Free.php:58
actionadd_meta_boxesCMF_Free.php:60
actionsave_postCMF_Free.php:61
actionupdate_postCMF_Free.php:62
filterthe_contentCMF_Free.php:65
filtercmf_meta_after_contentCMF_Free.php:70
filtercmf_meta_header_arrCMF_Pro.php:6
actionactivated_pluginpackage\cminds-free.php:31
actionadmin_initpackage\cminds-free.php:33
actionadmin_menupackage\cminds-free.php:34
actionadmin_enqueue_scriptspackage\cminds-free.php:35
actionadmin_enqueue_scriptspackage\cminds-free.php:36
actioncminds_download_sysinfopackage\cminds-free.php:48
actioninitpackage\cminds-free.php:50
actioninitpackage\cminds-free.php:51
filterplugin_row_metapackage\cminds-free.php:59
actionwp_dashboard_setuppackage\cminds-free.php:62
actionadmin_footerpackage\cminds-free.php:157
filterwp_mail_content_typepackage\cminds-free.php:311
filterwp_mail_content_typepackage\cminds-free.php:2075
filterwp_mail_content_typepackage\cminds-free.php:2166
actionadmin_enqueue_scriptssettings\CMF_Settings.php:18
actionadmin_menusettings\CMF_Settings.php:20
actionadmin_menuwizard.php:158
actionadmin_enqueue_scriptswizard.php:160
actionadmin_print_styleswizard.php:161
Maintenance & Trust

CM Footnotes – Boost your content’s credibility with footnotes, citations, and bibliography Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 29, 2026
PHP min version5.2.4
Downloads16K

Community Trust

Rating84/100
Number of ratings6
Active installs100
Developer Profile

CM Footnotes – Boost your content’s credibility with footnotes, citations, and bibliography Developer Profile

CreativeMindsSolutions

19 plugins · 22K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
535 days
View full developer profile
Detection Fingerprints

How We Detect CM Footnotes – Boost your content’s credibility with footnotes, citations, and bibliography

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cm-footnotes/assets/css/font.css/wp-content/plugins/cm-footnotes/assets/css/style.css/wp-content/plugins/cm-footnotes/assets/js/editor.js/wp-content/plugins/cm-footnotes/assets/js/front.js/wp-content/plugins/cm-footnotes/assets/js/settings.js
Script Paths
/wp-content/plugins/cm-footnotes/assets/js/editor.js/wp-content/plugins/cm-footnotes/assets/js/front.js/wp-content/plugins/cm-footnotes/assets/js/settings.js
Version Parameters
/wp-content/plugins/cm-footnotes/assets/css/font.css?ver=/wp-content/plugins/cm-footnotes/assets/css/style.css?ver=/wp-content/plugins/cm-footnotes/assets/js/editor.js?ver=/wp-content/plugins/cm-footnotes/assets/js/front.js?ver=/wp-content/plugins/cm-footnotes/assets/js/settings.js?ver=

HTML / DOM Fingerprints

CSS Classes
cmf-simple-footnotecmf-simple-footnote-definitionscmf-simple-footnote-label
Data Attributes
data-cmf-simple-footnote-id
JS Globals
CMF_front
Shortcode Output
[cm_simple_footnote]
FAQ

Frequently Asked Questions about CM Footnotes – Boost your content’s credibility with footnotes, citations, and bibliography