Note – A live edit text widget Security & Risk Analysis

wordpress.org/plugins/note

Note is a simple and easy to use widget for editing bits of text, live, in your WordPress front-end Customizer.

1K active installs v1.4.7 PHP + WP 4.3+ Updated Jun 6, 2018
customizerlive-editnotewidgetwysiwyg
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Note – A live edit text widget Safe to Use in 2026?

Generally Safe

Score 85/100

Note – A live edit text widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "note" plugin v1.4.7 exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength, indicating a minimal attack surface. The code also demonstrates good practices by using prepared statements for all SQL queries, avoiding dangerous functions, and having no file operations or external HTTP requests, all of which reduce common attack vectors. The lack of recorded vulnerabilities, including CVEs, further suggests a history of secure development.

However, a notable concern is the output escaping, where only 65% of outputs are properly escaped. This leaves room for potential Cross-Site Scripting (XSS) vulnerabilities, especially if the remaining unescaped outputs handle user-supplied data without further sanitization. Additionally, the complete absence of nonce checks and capability checks across all entry points (though there are no identified entry points) indicates a potential lack of security controls if any new entry points are introduced or if the static analysis is incomplete. The bundling of TinyMCE, while a common library, should be monitored for its own security updates.

In conclusion, the "note" plugin v1.4.7 is generally secure, with its primary weakness being the incomplete output escaping. The absence of exploitable entry points and a clean vulnerability history are positive indicators. The plugin developers have implemented good practices in critical areas like SQL and avoiding dangerous functions. The risk is moderate, primarily stemming from the potential for XSS due to insufficient output escaping.

Key Concerns

  • Insufficient output escaping
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Note – A live edit text widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Note – A live edit text widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
41
75 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

65% escaped116 total outputs
Attack Surface

Note – A live edit text widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 34
actionadmin_initincludes\admin\class-note-admin-install.php:44
actionadmin_menuincludes\admin\class-note-admin-options.php:53
actionadmin_menuincludes\admin\class-note-admin-options.php:54
actionadmin_enqueue_scriptsincludes\admin\class-note-admin-options.php:55
filterwp_redirectincludes\admin\class-note-admin-options.php:56
actionadmin_initincludes\admin\class-note-admin-options.php:57
actioninitincludes\class-note-customizer.php:108
actionwp_loadedincludes\class-note-customizer.php:109
actioncustomize_registerincludes\class-note-customizer.php:110
actioncustomize_controls_enqueue_scriptsincludes\class-note-customizer.php:111
actioncustomize_controls_print_footer_scriptsincludes\class-note-customizer.php:112
actioncustomize_preview_initincludes\class-note-customizer.php:113
filteroption_sidebars_widgetsincludes\class-note-customizer.php:713
actionwpincludes\class-note-customizer.php:892
actionwp_enqueue_scriptsincludes\class-note-customizer.php:893
actiondynamic_sidebar_paramsincludes\class-note-customizer.php:894
actionwp_footerincludes\class-note-customizer.php:895
actionwp_print_footer_scriptsincludes\class-note-customizer.php:896
actionwp_print_footer_scriptsincludes\class-note-customizer.php:897
actionwp_enqueue_scriptsincludes\class-note-scripts-styles.php:44
actionafter_switch_themeincludes\class-note-sidebars.php:80
actionwidgets_initincludes\class-note-sidebars.php:81
filternote_sidebar_locationsincludes\class-note-sidebars.php:82
actionwpincludes\class-note-sidebars.php:83
actionloop_startincludes\class-note-sidebars.php:84
actionloop_endincludes\class-note-sidebars.php:85
filterpre_update_option_sidebars_widgetsincludes\class-note-sidebars.php:106
filterpost_thumbnail_htmlincludes\class-note-sidebars.php:267
filterthe_contentincludes\class-note-sidebars.php:275
filternote_sidebar_ui_buttonsincludes\class-note-sidebars.php:334
actionadmin_enqueue_scriptsincludes\widgets\class-note-widget.php:467
actionnote_widgetincludes\widgets\class-note-widget.php:469
actionnote_widget_afterincludes\widgets\class-note-widget.php:471
actionwidgets_initnote.php:56
Maintenance & Trust

Note – A live edit text widget Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJun 6, 2018
PHP min version
Downloads111K

Community Trust

Rating96/100
Number of ratings6
Active installs1K
Developer Profile

Note – A live edit text widget Developer Profile

Slocum Studio

2 plugins · 2K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Note – A live edit text widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Note – A live edit text widget