Footnotes Made Easy Security & Risk Analysis

wordpress.org/plugins/footnotes-made-easy

Allows post authors to easily add and manage footnotes in posts.

2K active installs v3.1.0 PHP 7.4+ WP 4.6+ Updated Nov 29, 2025
bibliographyfootnotesformattingreference
97
A · Safe
CVEs total1
Unpatched0
Last CVENov 3, 2025
Safety Verdict

Is Footnotes Made Easy Safe to Use in 2026?

Generally Safe

Score 97/100

Footnotes Made Easy has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 3, 2025Updated 4mo ago
Risk Assessment

The static analysis of "footnotes-made-easy" v3.1.0 reveals an excellent security posture regarding its current code. The absence of any identified dangerous functions, file operations, or external HTTP requests is a significant strength. Furthermore, the complete use of prepared statements for SQL queries, 100% proper output escaping, and the presence of nonce checks and capability checks indicate strong defensive programming practices. The total entry points are zero, meaning there are no publicly exposed interfaces for direct exploitation through AJAX, REST API, shortcodes, or cron events in the analyzed version.

However, the vulnerability history presents a concern. A known high-severity vulnerability exists, although it is currently marked as unpatched in the provided history. This indicates a past weakness that, while potentially addressed in later versions or a separate patch, is a critical point of attention for this specific version (v3.1.0). The common vulnerability type being Cross-site Scripting (XSS) is particularly relevant as it often exploits unescaped output or improper input handling, which is contrary to the current static analysis findings. This suggests that the specific vulnerability might have been in a different version or a historical issue that has been remediated. The last vulnerability timestamp is in the future (2025-11-03), which is likely an data anomaly and should be disregarded when assessing current risk based on the "currently unpatched: 0" status.

In conclusion, while the current codebase of "footnotes-made-easy" v3.1.0 appears highly secure based on static analysis, the historical presence of a high-severity XSS vulnerability, even if marked as unpatched in the past, necessitates caution. The excellent coding practices observed in the static analysis are commendable, but users should verify that the specific version they are using has definitively addressed any historical security flaws to maintain a robust security posture.

Key Concerns

  • High severity vulnerability history
Vulnerabilities
1

Footnotes Made Easy Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2025-11733high · 7.2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Footnotes Made Easy <= 3.0.7 - Unauthenticated Stored Cross-Site Scripting

Nov 3, 2025 Patched in 3.0.8 (17d)
Code Analysis
Analyzed Mar 16, 2026

Footnotes Made Easy Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
52 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped52 total outputs
Attack Surface

Footnotes Made Easy Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_enqueue_scriptsfootnotes-made-easy.php:36
actionadmin_initfootnotes-made-easy.php:115
actionthe_contentfootnotes-made-easy.php:118
actionadmin_menufootnotes-made-easy.php:119
actionwp_headfootnotes-made-easy.php:120
actionwp_enqueue_scriptsfootnotes-made-easy.php:121
filterplugin_action_linksfootnotes-made-easy.php:123
filterplugin_row_metafootnotes-made-easy.php:124
filteradmin_footer_textfootnotes-made-easy.php:127
filterupdate_footerfootnotes-made-easy.php:128
Maintenance & Trust

Footnotes Made Easy Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 29, 2025
PHP min version7.4
Downloads55K

Community Trust

Rating92/100
Number of ratings38
Active installs2K
Developer Profile

Footnotes Made Easy Developer Profile

Patrick Lumumba

3 plugins · 2K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
17 days
View full developer profile
Detection Fingerprints

How We Detect Footnotes Made Easy

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/footnotes-made-easy/css/dbad.css
Version Parameters
footnotes-made-easy/css/dbad.css?ver=dbad.css?ver=

HTML / DOM Fingerprints

JS Globals
swas_wp_footnotes
FAQ

Frequently Asked Questions about Footnotes Made Easy