
Notely Security & Risk Analysis
wordpress.org/plugins/notelyCreate admin text notes for any post, page or custom post type.
Is Notely Safe to Use in 2026?
Mostly Safe
Score 78/100Notely is generally safe to use. 1 past CVE were resolved. Keep it updated.
The plugin "notely" v1.9.0 presents a mixed security posture. On the positive side, static analysis reveals a clean code base with no identified dangerous functions, no raw SQL queries, and a high percentage of properly escaped output. The absence of file operations and external HTTP requests further reduces potential attack vectors. The presence of nonce and capability checks, although limited, indicates an awareness of security best practices. However, a significant concern arises from the plugin's vulnerability history. A known medium severity Cross-Site Scripting (XSS) vulnerability from 2025-09-26 remains unpatched, which is a critical security flaw that attackers could exploit. This suggests a potential lack of rigorous security testing or a delayed patching process within the development cycle, even though the current code analysis shows no immediate vulnerabilities.
Key Concerns
- Unpatched medium severity CVE
Notely Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Notely <= 1.8.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Notely Code Analysis
Output Escaping
Notely Attack Surface
WordPress Hooks 12
Maintenance & Trust
Notely Maintenance & Trust
Maintenance Signals
Community Trust
Notely Alternatives
Page & Post Notes
page-post-notes
Simple plugin that allow you to notes on pages and posts
Beckin Post Notes
beckin-post-notes
Add private admin notes to posts, pages, and custom post types - simple, fast, and clutter-free.
Simple Post Notes
simple-post-notes
Adds simple notes to post, page and custom post type edit screen.
Plugin Notes Plus
plugin-notes-plus
Adds a column to the Plugins page where you can add, edit, or delete notes about a plugin.
Plugin Notes
plugin-notes
Allows you to add notes to plugins.
Notely Developer Profile
3 plugins · 14K total installs
How We Detect Notely
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/notely/css/notely.cssnotely/css/notely.css?ver=HTML / DOM Fingerprints
notely-iconnotely-preservenote-icon-notely-preserve-shownid="notelyfield"name="notelyfield"jQuery