
Guan Image Notes Security & Risk Analysis
wordpress.org/plugins/guan-image-notesImage tagging system sync with WordPress comment system. Or also known as image notes, or image annotation.
Is Guan Image Notes Safe to Use in 2026?
Generally Safe
Score 85/100Guan Image Notes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "guan-image-notes" v2.0 plugin exhibits a mixed security posture. On the positive side, it has no recorded vulnerabilities (CVEs) and boasts a limited attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed. However, the static analysis reveals significant concerns within the code itself. The presence of two taint flows with unsanitized paths, both categorized as high severity, is a critical finding and suggests a direct pathway for malicious input to be processed insecurely. Furthermore, the plugin only uses prepared statements for 25% of its SQL queries, and only 23% of output is properly escaped, indicating potential for SQL injection and Cross-Site Scripting (XSS) vulnerabilities respectively.
The vulnerability history showing zero CVEs is encouraging but could be misleading given the identified code-level risks. It might suggest that these specific types of vulnerabilities haven't been discovered or reported yet, rather than indicating an inherently secure codebase. The plugin's strengths lie in its minimal attack surface and lack of historical issues, but these are overshadowed by the critical taint flows and concerning practices in SQL query handling and output escaping. Users should proceed with caution and be aware of the potential for exploitation due to these code-level weaknesses.
Key Concerns
- High severity taint flows with unsanitized paths
- Only 25% of SQL queries use prepared statements
- Only 23% of output is properly escaped
- No nonce checks found
Guan Image Notes Security Vulnerabilities
Guan Image Notes Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Guan Image Notes Attack Surface
WordPress Hooks 6
Maintenance & Trust
Guan Image Notes Maintenance & Trust
Maintenance Signals
Community Trust
Guan Image Notes Alternatives
demon image annotation
demon-image-annotation
Allows you to add textual annotations to images by select a region of the image and then attach a textual description.
Image Annotations
image-annotations
Image Annotations plugin lets readers to leave annotations to the selected area of the image in comments.
Comment Image
comment-image
Enable readers to attach an image to their comments.
Embed Images in Comments
embed-comment-images
Embed direct image links in your comments with an img tag.
Comment-Images
wordpress-comment-images
Comment Image Embedder is a very simple plugin that, once installed, lets your visitors add an image to their comments.
Guan Image Notes Developer Profile
1 plugin · 10 total installs
How We Detect Guan Image Notes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/guan-image-notes/js/jquery.annotate.js/wp-content/plugins/guan-image-notes/js/jquery-ui-1.7.1.js/wp-content/plugins/guan-image-notes/css/annotation.csshttp://ajax.googleapis.com/ajax/libs/jquery/1.3/jquery.min.jsHTML / DOM Fingerprints
image-note-thumbnailGuan Image Notes | Add notes tagging to your images in WordPress powered blogs.This program is free software; you can redistribute it and/ormodify it under the terms of the GNU General Public Licenseas published by the Free Software Foundation; either version 2+18 moreid="img-addableid='comment-id="comment-id="img-jQuery