GR Dashboard Notes Security & Risk Analysis

wordpress.org/plugins/gr-dashboard-notes

This plugin let you create notes on the dashboard for different roles of your choice.

10 active installs v1.0.4 PHP + WP 4.6+ Updated Sep 17, 2023
dashboardnotenotesnoticenotices
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GR Dashboard Notes Safe to Use in 2026?

Generally Safe

Score 85/100

GR Dashboard Notes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The plugin 'gr-dashboard-notes' v1.0.4 exhibits a strong security posture based on the provided static analysis. The absence of any identified attack surface (AJAX handlers, REST API routes, shortcodes, cron events) significantly reduces the potential for external exploitation. Furthermore, the code demonstrates good security practices with 100% of SQL queries using prepared statements, a high percentage of properly escaped output, and the presence of nonce and capability checks. The plugin also avoids dangerous functions, file operations, and external HTTP requests, all of which are positive indicators.

Despite the generally robust findings, the lack of identified vulnerabilities in its history is a positive sign, suggesting a history of secure development. However, it's important to note that a lack of past vulnerabilities does not guarantee future security. The low number of analyzed taint flows and the absence of any critical or high severity issues in the taint analysis are encouraging. The plugin's strengths lie in its minimal attack surface and adherence to secure coding principles. The main potential weakness, albeit minor given the other strengths, is the number of total outputs, where a small percentage (5%) were not properly escaped. This, while not a critical finding here, could become an issue if the number of outputs were much larger or if those unescaped outputs handled sensitive data.

Key Concerns

  • Minor output unescaped
Vulnerabilities
None known

GR Dashboard Notes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

GR Dashboard Notes Release Timeline

v1.0.4Current
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

GR Dashboard Notes Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
41 escaped
Nonce Checks
7
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped43 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

3 flows
gr_dashboard_notes_admin_ansicht_einstellungen (inc\gr-admin-menu.php:5)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

GR Dashboard Notes Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioncurrent_screengr-dashboard-notes.php:43
actionadmin_menuinc\gr-admin-menu.php:4
Maintenance & Trust

GR Dashboard Notes Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedSep 17, 2023
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

GR Dashboard Notes Developer Profile

Felln

2 plugins · 210 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GR Dashboard Notes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
notice-info
FAQ

Frequently Asked Questions about GR Dashboard Notes