
Frontend User Notes Security & Risk Analysis
wordpress.org/plugins/frontend-user-notesAllow site members to add and save personal notes from frontend. Suited for membership and e-learning sites. Fast, secure and fully ajax loading.
Is Frontend User Notes Safe to Use in 2026?
Generally Safe
Score 99/100Frontend User Notes has a strong security track record. Known vulnerabilities have been patched promptly.
The "frontend-user-notes" plugin version 2.1.1 exhibits a generally strong security posture based on static analysis, with no identified dangerous functions, SQL injection vulnerabilities, file operations, or external HTTP requests. The plugin demonstrates good practices by utilizing prepared statements for all SQL queries and implementing nonce and capability checks on its entry points. A high percentage of output escaping (86%) is also a positive sign. However, the presence of 3 AJAX handlers, while all reportedly checked for authentication, still represents an attack surface that requires careful ongoing scrutiny. The plugin's history includes one known CVE, which was an Authorization Bypass Through User-Controlled Key vulnerability. While this CVE is currently unpatched, its severity was only medium. The fact that the last vulnerability occurred in the future (2026-02-17) is an anomaly and should be investigated as a data integrity issue rather than a current security threat.
Key Concerns
- One known CVE recorded
- Medium severity CVE
- 86% output escaping
- 3 AJAX handlers present
Frontend User Notes Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Frontend User Notes <= 2.1.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Note Modification
Frontend User Notes Code Analysis
Bundled Libraries
Output Escaping
Frontend User Notes Attack Surface
AJAX Handlers 3
Shortcodes 1
WordPress Hooks 13
Maintenance & Trust
Frontend User Notes Maintenance & Trust
Maintenance Signals
Community Trust
Frontend User Notes Alternatives
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
ultimate-member
Membership & community plugin with user profiles, registration & login, member directories, content restriction, user roles and much more.
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
wp-user-avatar
Setup paid membership, accept payment, sell subscription & digital product, paywall, create login & registration form, user profile & member directory
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder
user-registration
Build membership sites with tiered plans, content restriction, drag-&-drop custom registration & login form builder, and built-in payment system.
Ultimate Member – reCAPTCHA
um-recaptcha
Stop bots on your registration & login forms with Google reCAPTCHA
User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration
wp-user-frontend
Create forms, guest posts, subscriptions, user directory, user registration, membership, frontend posts, profile builder, content restriction rules.
Frontend User Notes Developer Profile
3 plugins · 700 total installs
How We Detect Frontend User Notes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/frontend-user-notes/admin/css/funp_admin_styles.css/wp-content/plugins/frontend-user-notes/admin/js/funp_admin_scripts.js/wp-content/plugins/frontend-user-notes/includes/css/style.css/wp-content/plugins/frontend-user-notes/includes/css/datatables.min.css/wp-content/plugins/frontend-user-notes/includes/js/jquery.dataTables.min.js/wp-content/plugins/frontend-user-notes/includes/js/main.js/wp-content/plugins/frontend-user-notes/includes/js/notes.js/wp-content/plugins/frontend-user-notes/admin/js/funp_admin_scripts.js/wp-content/plugins/frontend-user-notes/includes/js/jquery.dataTables.min.js/wp-content/plugins/frontend-user-notes/includes/js/main.js/wp-content/plugins/frontend-user-notes/includes/js/notes.jsfrontend-user-notes/admin/css/funp_admin_styles.css?ver=frontend-user-notes/admin/js/funp_admin_scripts.js?ver=frontend-user-notes/includes/css/style.css?ver=frontend-user-notes/includes/css/datatables.min.css?ver=frontend-user-notes/includes/js/jquery.dataTables.min.js?ver=frontend-user-notes/includes/js/main.js?ver=frontend-user-notes/includes/js/notes.js?ver=HTML / DOM Fingerprints
funp-notes-wrapperfunp-add-note-formfunp-note-list<!-- Frontend User Notes Plugin --><!-- Start Frontend User Notes --><!-- End Frontend User Notes -->data-funp-noncedata-funp-actiondata-funp-post-idfunp_ajax_objectfrontend_notes_obj/wp-json/funp/v1/notes[frontend_user_notes]