
Footnote Drawer Security & Risk Analysis
wordpress.org/plugins/footnote-drawerFootnote Drawer displays footnotes in the drawer UI.
Is Footnote Drawer Safe to Use in 2026?
Generally Safe
Score 85/100Footnote Drawer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "footnote-drawer" v1.0.4 plugin exhibits a generally strong security posture based on the provided static analysis. There are no identified dangerous functions, all SQL queries utilize prepared statements, and there are no file operations or external HTTP requests, which significantly reduces the attack surface. The absence of any known CVEs further contributes to its good standing.
However, several areas present potential concerns. The plugin lacks nonce checks and capability checks, meaning that actions initiated by its entry points (shortcodes) are not protected against Cross-Site Request Forgery (CSRF) attacks or unauthorized access based on user roles. Additionally, while the number of output escaping instances is low, a significant portion (33%) is not properly escaped, introducing a risk of Stored Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is outputted without sanitization.
The vulnerability history shows no recorded issues, which is positive. This, combined with the absence of critical taint flows, suggests that the plugin's core functionality is likely secure. Nevertheless, the lack of specific security controls like nonces and capability checks, along with the identified output escaping issues, are weaknesses that should be addressed to further harden the plugin's security.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Unescaped output detected
Footnote Drawer Security Vulnerabilities
Footnote Drawer Code Analysis
Output Escaping
Footnote Drawer Attack Surface
Shortcodes 2
WordPress Hooks 5
Maintenance & Trust
Footnote Drawer Maintenance & Trust
Maintenance Signals
Community Trust
Footnote Drawer Alternatives
Citation Note
citation-note
Easily add, manage, and display citations, references, and footnotes in posts, pages, or custom post types using a user-friendly editor interface.
Easy Footnotes
easy-footnotes
Easy Footnotes lets you quickly and easily add footnotes throughout your WordPress posts using a simple shortcode in the text editor.
Modern Footnotes
modern-footnotes
Add inline footnotes to your posts. On desktop, the footnotes will appear as tooltips. On mobile, the footnote will expand beneath the text.
Footnotes Made Easy
footnotes-made-easy
Allows post authors to easily add and manage footnotes in posts.
FD Footnotes Plugin
fd-footnotes
Add elegant looking footnotes to your posts simply and naturally.
Footnote Drawer Developer Profile
2 plugins · 10 total installs
How We Detect Footnote Drawer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/footnote-drawer/includes/css/style.css/wp-content/plugins/footnote-drawer/includes/js/index.js/wp-content/plugins/footnote-drawer/includes/js/index.jsfootnote-drawer/includes/js/index.js?ver=footnote-drawer/includes/css/style.css?ver=HTML / DOM Fingerprints
footnote-drawer-referencefootnote-drawer-scroll-upfootnote-drawer-endnotes-contentsfootnote-drawer-endnotesdata-footnote-drawer-numberdata-footnote-drawer-tofootnote_drawer<a href="#[fnd_end]