
Notes Security & Risk Analysis
wordpress.org/plugins/notesDisplays notes on the WordPress dashboard. When the date of the event has occurred, the note is colored red.
Is Notes Safe to Use in 2026?
Generally Safe
Score 85/100Notes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "notes" plugin v1.1.0 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the plugin demonstrates excellent SQL hygiene by utilizing prepared statements for all database interactions and avoids risky operations like file modifications or external HTTP requests. The vulnerability history is also clean, with no recorded CVEs, suggesting a history of secure development practices.
However, a notable concern arises from the output escaping analysis, where 40% of identified outputs are not properly escaped. This indicates a potential for cross-site scripting (XSS) vulnerabilities, especially if user-supplied data is reflected directly in the output without adequate sanitization. While the taint analysis shows no critical or high severity flows, the lack of nonce checks and capability checks on entry points (though there are none listed, this is a general best practice to consider) also represent potential areas for improvement in a more complex plugin. The plugin's strengths lie in its minimal attack surface and robust SQL handling, but the output escaping weakness requires attention to prevent potential client-side attacks.
Key Concerns
- Unescaped output detected
- Missing nonce checks (general practice)
- Missing capability checks (general practice)
Notes Security Vulnerabilities
Notes Release Timeline
Notes Code Analysis
Output Escaping
Notes Attack Surface
WordPress Hooks 5
Maintenance & Trust
Notes Maintenance & Trust
Maintenance Signals
Community Trust
Notes Alternatives
LH Dashboard Notes
lh-dashboard-notes
Allows you to create and edit notes that appear on the admin dashboard
Quick Notes
wp-quick-notes
Allow users to write down notes on frontend.
Sticky Notes for WP Dashboard
wb-sticky-notes
Create sticky notes in your WP admin for reminders and to-dos. Restrict notes by user roles and disable them on specific pages.
User Notes
user-notes
Keep private notes about each of your users that only Administrators can see.
Simple Admin Notes
simple-admin-notes
Adds a simple "Notes" section to the admin menu or posts
Notes Developer Profile
74 plugins · 10K total installs
How We Detect Notes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/notes/js/datepicker.js/wp-content/plugins/notes/css/note.css/wp-content/plugins/notes/js/datepicker.jsHTML / DOM Fingerprints
notes-tablenotecont-notesnote-submitss-logonew-custom-notename="note_name_"name="note_datepicker_"class="datepicker"class="note"id="notes-plugin"class="s-img-logo"+2 more<h2>SEOS THEMES</h2><h3>Today is: