
Page & Post Notes Security & Risk Analysis
wordpress.org/plugins/page-post-notesSimple plugin that allow you to notes on pages and posts
Is Page & Post Notes Safe to Use in 2026?
Generally Safe
Score 99/100Page & Post Notes has a strong security track record. Known vulnerabilities have been patched promptly.
The "page-post-notes" plugin v1.3.5 presents a mixed security posture. While the static analysis indicates a positive trend with a large percentage of outputs properly escaped and a robust implementation of nonces and capability checks, there are significant concerns regarding its handling of SQL queries. All observed SQL queries are executed without prepared statements, which, even with the absence of identified taint flows in this analysis, poses a substantial risk of SQL injection vulnerabilities. The plugin's vulnerability history, though currently showing no unpatched CVEs, reveals a past medium-severity vulnerability attributed to Missing Authorization. This historical context, combined with the lack of prepared statements, suggests a potential for recurring authorization or injection issues if not addressed rigorously.
Overall, the plugin demonstrates good practices in areas like output escaping and authentication checks on its entry points. However, the universal reliance on raw SQL queries is a critical weakness that elevates the risk profile. The absence of taint analysis findings in this specific scan doesn't negate the inherent danger of unsanitized SQL. A proactive approach focusing on refactoring SQL queries to use prepared statements is strongly recommended to mitigate these risks and improve the plugin's long-term security.
Key Concerns
- SQL queries do not use prepared statements
- Past medium severity vulnerability (Missing Authorization)
Page & Post Notes Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Page & Post Notes <= 1.3.4 - Missing Authorization to Authenticated (Subscriber+) Note Update/Deletion
Page & Post Notes Code Analysis
SQL Query Safety
Output Escaping
Page & Post Notes Attack Surface
AJAX Handlers 3
WordPress Hooks 5
Maintenance & Trust
Page & Post Notes Maintenance & Trust
Maintenance Signals
Community Trust
Page & Post Notes Alternatives
Notely
notely
Create admin text notes for any post, page or custom post type.
Beckin Post Notes
beckin-post-notes
Add private admin notes to posts, pages, and custom post types - simple, fast, and clutter-free.
Simple Post Notes
simple-post-notes
Adds simple notes to post, page and custom post type edit screen.
Plugin Notes Plus
plugin-notes-plus
Adds a column to the Plugins page where you can add, edit, or delete notes about a plugin.
Plugin Notes
plugin-notes
Allows you to add notes to plugins.
Page & Post Notes Developer Profile
11 plugins · 51K total installs
How We Detect Page & Post Notes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/page-post-notes/include/admin-output.php/wp-content/plugins/page-post-notes/include/functions.php/wp-content/plugins/page-post-notes/include/install.php/wp-content/plugins/page-post-notes/include/insert-to-db.php/wp-content/plugins/page-post-notes/include/script.php/wp-content/plugins/page-post-notes/include/settings.php/wp-content/plugins/page-post-notes/include/style.php/wp-content/plugins/page-post-notes/notices.php/wp-content/plugins/page-post-notes/include/script.phpHTML / DOM Fingerprints
<!-- Start: YYDevelopment Page/Post Notes --><!-- End: YYDevelopment Page/Post Notes --><!-- Start: Dashboard Notes --><!-- End: Dashboard Notes -->data-page-iddata-post-idyydev_notes_ajax_object/wp-json/yydev-notes/v1/save