
Endnotes Security & Risk Analysis
wordpress.org/plugins/endnotesEasily add footnotes to your posts and pages.
Is Endnotes Safe to Use in 2026?
Generally Safe
Score 85/100Endnotes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "endnotes" plugin v1.0.1 exhibits a generally strong security posture based on the static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the code signals indicate good practices such as the exclusive use of prepared statements for SQL queries and the presence of capability checks. The lack of file operations and external HTTP requests also reduces potential exposure points.
However, a notable concern arises from the output escaping. With 50% of outputs not being properly escaped, there's a risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is directly rendered without adequate sanitization. The static analysis also reveals zero taint flows, which is positive, but this does not negate the risk identified in the unescaped outputs, as taint analysis might not always capture all potential XSS vectors, especially in simpler plugins.
The vulnerability history is clean, with no recorded CVEs. This suggests either a history of secure development or potentially a lack of deep security auditing. The combination of a limited attack surface and no past vulnerabilities is a positive indicator. Nevertheless, the unescaped output remains a concrete risk that requires attention. In conclusion, while "endnotes" v1.0.1 has a good foundation and a clean history, the 50% rate of unescaped output presents a clear and present danger that should be addressed to ensure a truly robust security profile.
Key Concerns
- Unescaped output present
Endnotes Security Vulnerabilities
Endnotes Code Analysis
Output Escaping
Endnotes Attack Surface
WordPress Hooks 6
Maintenance & Trust
Endnotes Maintenance & Trust
Maintenance Signals
Community Trust
Endnotes Alternatives
Simple Footnotes
simple-footnotes
Create simple, elegant footnotes on your site. Use the [ref] shortcode and the plugin takes care of the rest.
CM Footnotes – Boost your content’s credibility with footnotes, citations, and bibliography
cm-footnotes
Add and manage footnotes, citations, and bibliography with this footnotes Plugin. Improve clarity and provide references.
Better Footnotes
better-footnotes
A robust solution to provide a fast reference and link to additional information for your readers
CiteKit – Citation and Reference Manager
citation-reference-manager
Add in-text citations, tooltips, and auto-generated bibliography to your WordPress posts in APA, MLA, Chicago and more.
Footnotes Made Easy
footnotes-made-easy
Allows post authors to easily add and manage footnotes in posts.
Endnotes Developer Profile
1 plugin · 100 total installs
How We Detect Endnotes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/endnotes/js/endnotes.js/wp-content/plugins/endnotes/js/endnotes.jsendnotes.js?ver=1.0.0