
Notes Widget Wrapper Security & Risk Analysis
wordpress.org/plugins/notes-widget-wrapperApply a "sticky note" style box around your widget content. All text is displayed in hand writing font too.
Is Notes Widget Wrapper Safe to Use in 2026?
Generally Safe
Score 85/100Notes Widget Wrapper has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'notes-widget-wrapper' plugin v1.2.2 exhibits a generally good security posture based on the provided static analysis. It has no recorded vulnerabilities (CVEs) and the static analysis reveals no dangerous functions, direct SQL queries (all use prepared statements), file operations, or external HTTP requests. The absence of an attack surface for AJAX, REST API, shortcodes, and cron events is a significant strength, indicating that there are no readily exposed entry points for attackers. Taint analysis also shows no identified issues.
However, there are notable areas for concern. A critical weakness is the extremely low percentage (11%) of properly escaped output. With 65 total outputs, this means a significant number of them are likely vulnerable to Cross-Site Scripting (XSS) attacks. Furthermore, the complete lack of nonce checks and capability checks across all entry points (even though the attack surface is reported as 0) is a serious oversight. If any entry points were to be discovered or introduced in future versions, they would be entirely unprotected against unauthorized access and manipulation. While the current lack of vulnerabilities is positive, the significant output escaping and authorization check deficiencies represent substantial risks that could be exploited if new attack vectors are found or if the plugin's scope expands.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks on any entry points
- No capability checks on any entry points
Notes Widget Wrapper Security Vulnerabilities
Notes Widget Wrapper Code Analysis
Output Escaping
Notes Widget Wrapper Attack Surface
WordPress Hooks 12
Maintenance & Trust
Notes Widget Wrapper Maintenance & Trust
Maintenance Signals
Community Trust
Notes Widget Wrapper Alternatives
Sticky Note by Dolar Patel
sticky-notes
A Simple plugin to generate Notice Text using Widget.
Dashboard Notepad
dashboard-notepad
The very simplest of notepads for your Dashboard.
Dashboard Widgets Suite
dashboard-widgets-suite
Adds 9 awesome widgets to your WP Dashboard. Includes User Notes, Social Buttons, System Info, Debug/Error Logs, and more!
Dashboard Sticky Notes
dashboard-sticky-notes
This plugin adds the functionality to add sticky notes into the dashboard.
Contact Form 7 styler for Elementor Page Builder
elementor-contact-form-7
Style your Contact Form 7 forms right from the Elementor visual editor.
Notes Widget Wrapper Developer Profile
6 plugins · 1K total installs
How We Detect Notes Widget Wrapper
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/notes-widget-wrapper/admin/css/notes-widget-wrapper-admin.css/wp-content/plugins/notes-widget-wrapper/public/css/notes-widget-wrapper-public.css/wp-content/plugins/notes-widget-wrapper/public/js/notes-widget-wrapper-public.js/wp-content/plugins/notes-widget-wrapper/admin/js/notes-widget-wrapper-admin.jsnotes-widget-wrapper/admin/css/notes-widget-wrapper-admin.css?ver=notes-widget-wrapper/public/css/notes-widget-wrapper-public.css?ver=notes-widget-wrapper/public/js/notes-widget-wrapper-public.js?ver=notes-widget-wrapper/admin/js/notes-widget-wrapper-admin.js?ver=HTML / DOM Fingerprints
notes-widget-wrapper-containernotes-widget-wrapper-contentdata-thumb-tack-colourdata-background-colourdata-text-colourdata-font-sizedata-font-styledata-iframe-height+1 morenotes_widget_wrapper_params