FundaMine Annotation Tool Security & Risk Analysis

wordpress.org/plugins/fundamine-inline-comments-highlights

FundaMine enables Medium.com style inline comments, highlights and tweetshots on blogs and media websites. All this with a one click install!

10 active installs v1.0.0 PHP + WP 3.0.1+ Updated Unknown
commentshighlightsresponsessidenotes
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FundaMine Annotation Tool Safe to Use in 2026?

Generally Safe

Score 100/100

FundaMine Annotation Tool has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The static analysis of the 'fundamine-inline-comments-highlights' v1.0.0 plugin reveals a strong security posture with no identified vulnerabilities in the code. The absence of dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, and the complete lack of exploitable entry points like AJAX handlers, REST API routes, and shortcodes are all positive indicators. Furthermore, the plugin demonstrates good practices by not relying on bundled libraries. The vulnerability history is also clean, with zero known CVEs, reinforcing the current security strength of this version.

While the code analysis and vulnerability history are excellent, the complete absence of nonce and capability checks across all zero entry points is a potential concern for future development or if new entry points are introduced. This means that if any entry points were to be added or if the plugin were to evolve, there would be no built-in security mechanisms to prevent unauthorized actions. However, based solely on the provided data for v1.0.0, the plugin appears to be secure and well-coded with a very low risk profile. The strength lies in its minimal attack surface and clean code, with the only noted weakness being the absence of protective checks which might become relevant later.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

FundaMine Annotation Tool Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

FundaMine Annotation Tool Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

FundaMine Annotation Tool Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwp_headbasics.php:12
Maintenance & Trust

FundaMine Annotation Tool Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

FundaMine Annotation Tool Developer Profile

tarkeshwarsingh

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect FundaMine Annotation Tool

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
https://www.fundamine.com/fundamineannotate?fmrequestorurl=

HTML / DOM Fingerprints

HTML Comments
<![if lt IE 9]>
JS Globals
window.location.href
FAQ

Frequently Asked Questions about FundaMine Annotation Tool