
Picnote Image Annotations Security & Risk Analysis
wordpress.org/plugins/picnote-image-annotationsAdd professional source attributions and licenses to images in your WordPress content with overlays and organized lists.
Is Picnote Image Annotations Safe to Use in 2026?
Generally Safe
Score 100/100Picnote Image Annotations has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "picnote-image-annotations" plugin v0.1.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and includes a reasonable number of nonce and capability checks for its identified entry points. The absence of file operations and external HTTP requests further reduces the attack surface in those areas. The taint analysis also shows no critical or high-severity unsanitized flows, indicating a careful approach to handling user input in the analyzed flows.
However, significant concerns arise from the "ATTACK SURFACE" analysis. Specifically, the plugin exposes two AJAX handlers that lack authentication checks. This presents a substantial risk, as any authenticated user, regardless of their role or permissions, could potentially trigger these handlers, leading to unintended actions or information disclosure. While the total number of entry points is small, the presence of unprotected AJAX endpoints is a critical weakness that must be addressed.
The vulnerability history being clear of any recorded CVEs is a positive sign, suggesting that past versions may have been developed with security in mind or have not yet been subject to significant public scrutiny. Despite the strengths in SQL handling and taint analysis, the unprotected AJAX handlers represent a clear and present danger. The plugin's overall security would be significantly improved by implementing proper authentication and authorization checks on these critical entry points.
Key Concerns
- Unprotected AJAX handlers
- Output escaping is only 56% proper
Picnote Image Annotations Security Vulnerabilities
Picnote Image Annotations Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Picnote Image Annotations Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 17
Maintenance & Trust
Picnote Image Annotations Maintenance & Trust
Maintenance Signals
Community Trust
Picnote Image Annotations Alternatives
FSM Custom Featured Image Caption
fsm-custom-featured-image-caption
Allows adding custom captions to the featured images of the posts.
Image Source Control Lite – Show Image Credits and Captions
image-source-control-isc
Show image credits, image captions, and copyrights. Manage image sources and warn if they are missing. The original plugin since 2012.
Image Source Overlay
image-source-overlay
With Image Source Overlay you can manage image sources in media library. Plugin will then generate small overlay for every image crediting the origina …
Image Rights
image-rights
Adds additional fields for setting image credits in the media library.
PicDefense.io – Your Guard Against Image Copyright Infringement
picdefense-io-image-copyright-risk-checker
Compile list of images on your Wordpress site and submit to PicDefense.io for copyright risk analysis.
Picnote Image Annotations Developer Profile
2 plugins · 0 total installs
How We Detect Picnote Image Annotations
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/picnote-image-annotations/assets/css/picnote.css/wp-content/plugins/picnote-image-annotations/assets/js/picnote.js/wp-content/plugins/picnote-image-annotations/assets/js/picnote.jspicnote-image-annotations/assets/css/picnote.css?ver=picnote-image-annotations/assets/js/picnote.js?ver=HTML / DOM Fingerprints
picnote-image-annotation-overlaypicnote-image-annotation-listdata-picnote-annotationPicnotepicnote_fs