Notely Security & Risk Analysis

wordpress.org/plugins/notely

Create admin text notes for any post, page or custom post type.

700 active installs v1.9.0 PHP + WP 4.0+ Updated Mar 4, 2026
memonotespage-notespost-notes
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVESep 26, 2025
Safety Verdict

Is Notely Safe to Use in 2026?

Mostly Safe

Score 78/100

Notely is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Sep 26, 2025Updated 1mo ago
Risk Assessment

The plugin "notely" v1.9.0 presents a mixed security posture. On the positive side, static analysis reveals a clean code base with no identified dangerous functions, no raw SQL queries, and a high percentage of properly escaped output. The absence of file operations and external HTTP requests further reduces potential attack vectors. The presence of nonce and capability checks, although limited, indicates an awareness of security best practices. However, a significant concern arises from the plugin's vulnerability history. A known medium severity Cross-Site Scripting (XSS) vulnerability from 2025-09-26 remains unpatched, which is a critical security flaw that attackers could exploit. This suggests a potential lack of rigorous security testing or a delayed patching process within the development cycle, even though the current code analysis shows no immediate vulnerabilities.

Key Concerns

  • Unpatched medium severity CVE
Vulnerabilities
1

Notely Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-60149medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Notely <= 1.8.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

Sep 26, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Notely Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
29 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

91% escaped32 total outputs
Attack Surface

Notely Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionadmin_initinc\settings-ui.php:18
actionadmin_menuinc\settings-ui.php:19
actionplugins_loadednotely.php:22
actionadd_meta_boxesnotely.php:29
actionsave_postnotely.php:30
actionadmin_enqueue_scriptsnotely.php:111
actionadmin_headnotely.php:129
filtermanage_posts_columnsnotely.php:133
actionmanage_posts_custom_columnnotely.php:155
filtermanage_pages_columnsnotely.php:183
actionmanage_pages_custom_columnnotely.php:201
actionadmin_noticesnotely.php:242
Maintenance & Trust

Notely Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 4, 2026
PHP min version
Downloads17K

Community Trust

Rating96/100
Number of ratings13
Active installs700
Developer Profile

Notely Developer Profile

Rocket Apps

3 plugins · 14K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
308 days
View full developer profile
Detection Fingerprints

How We Detect Notely

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/notely/css/notely.css
Version Parameters
notely/css/notely.css?ver=

HTML / DOM Fingerprints

CSS Classes
notely-iconnotely-preservenote-icon-notely-preserve-shown
Data Attributes
id="notelyfield"name="notelyfield"
JS Globals
jQuery
FAQ

Frequently Asked Questions about Notely