
Footnotes for WordPress Security & Risk Analysis
wordpress.org/plugins/footnotes-for-wordpressFootnotes for WordPress enables easy-to-use fancy footnotes for WordPress posts.
Is Footnotes for WordPress Safe to Use in 2026?
Use With Caution
Score 64/100Footnotes for WordPress has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "footnotes-for-wordpress" plugin version 2016.1230 presents a mixed security posture. On the positive side, the plugin exhibits strong practices regarding database interactions, with 100% of SQL queries utilizing prepared statements and no direct file operations or external HTTP requests detected. The static analysis also shows a limited attack surface with no identified AJAX handlers or REST API routes exposed without authentication. However, significant concerns arise from the lack of comprehensive output escaping, with only 29% of outputs properly escaped, indicating a strong potential for Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the absence of any nonce checks or capability checks across its entry points (shortcodes) is a critical oversight, leaving it susceptible to various attacks if input is not properly sanitized.
The vulnerability history is particularly concerning. The plugin has a known critical vulnerability history, specifically a medium severity Cross-Site Scripting (XSS) flaw, which remains unpatched according to the provided data. The fact that the last vulnerability was documented as recent (2025-04-01) and is still unaddressed suggests a lack of active maintenance and a high likelihood of existing exploitable weaknesses. While taint analysis shows no immediate critical or high severity flows, this is likely due to the static analysis being limited or the identified vulnerabilities not triggering the taint analysis rules. The combination of these factors, especially the unpatched XSS vulnerability and lack of robust input/output sanitization on shortcodes, creates a significant risk.
In conclusion, despite some good practices in areas like SQL handling, the "footnotes-for-wordpress" plugin version 2016.1230 is a high-risk component. The presence of an unpatched XSS vulnerability, coupled with insufficient output escaping and a complete lack of nonce and capability checks on its entry points, makes it a prime target for attackers. Users should exercise extreme caution and prioritize updating or replacing this plugin.
Key Concerns
- Unpatched CVE (Medium Severity XSS)
- Low percentage of properly escaped output
- No nonce checks
- No capability checks
Footnotes for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Footnotes for WordPress <= 2016.1230 - Authenticated (Contributor+) Stored Cross-Site Scripting
Footnotes for WordPress Code Analysis
Output Escaping
Footnotes for WordPress Attack Surface
Shortcodes 3
WordPress Hooks 3
Maintenance & Trust
Footnotes for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Footnotes for WordPress Alternatives
Footnotes Made Easy
footnotes-made-easy
Allows post authors to easily add and manage footnotes in posts.
Blank Footnotes
blank-footnotes
Simple plugin to show footnotes using markdown notation.
Footnotes & Content
awesome-footnotes
Allows post authors to easily add and manage footnotes in posts.
Advanced Editor Tools
tinymce-advanced
Extends and enhances the block editor (Gutenberg) and the classic editor (TinyMCE).
Advanced Excerpt
advanced-excerpt
Control the appearance of WordPress post excerpts
Footnotes for WordPress Developer Profile
2 plugins · 10K total installs
How We Detect Footnotes for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/footnotes-for-wordpress/footnote-voodoo.css/wp-content/plugins/footnotes-for-wordpress/footnote-voodoo.js/wp-content/plugins/footnotes-for-wordpress/footnoted.png/wp-content/plugins/footnotes-for-wordpress/note.png/wp-content/plugins/footnotes-for-wordpress/tip.png/wp-content/plugins/footnotes-for-wordpress/tip-down.png/wp-content/plugins/footnotes-for-wordpress/footnote-voodoo.jsfootnotes-for-wordpress/footnote-voodoo.css?ver=2016.1230footnotes-for-wordpress/footnote-voodoo.js?ver=2016.1230HTML / DOM Fingerprints
footnotenote-returnfootnoteddata-backlink-prefixtipUpUrltipDownUrl<ol class="footnotes"><li class="footnote"><a class="note-return" href="#<sup>[