
Plugin Notes Plus Security & Risk Analysis
wordpress.org/plugins/plugin-notes-plusAdds a column to the Plugins page where you can add, edit, or delete notes about a plugin.
Is Plugin Notes Plus Safe to Use in 2026?
Generally Safe
Score 91/100Plugin Notes Plus has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "plugin-notes-plus" v1.2.10 exhibits a mixed security posture. While it demonstrates good practices in handling SQL queries with prepared statements and has a high percentage of properly escaped output, significant concerns arise from its attack surface and taint analysis.
The static analysis reveals two AJAX handlers, both lacking authentication checks. This presents a direct entry point for unauthenticated attackers to potentially interact with plugin functionalities. The taint analysis further exacerbates this concern, identifying two flows with unsanitized paths that are classified as high severity. This indicates that user-supplied input in these flows is not being adequately validated or sanitized before being used, potentially leading to vulnerabilities like Cross-Site Scripting or other injection attacks.
The vulnerability history shows a pattern of past medium-severity vulnerabilities, including Missing Authorization and Cross-site Scripting. While there are currently no unpatched CVEs, the recurrence of these vulnerability types suggests a potential ongoing weakness in input validation and authorization mechanisms. The plugin's strengths lie in its robust SQL handling and output escaping, but the unprotected AJAX endpoints and high-severity taint flows represent immediate and critical risks that need to be addressed.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows with unsanitized paths
- History of Missing Authorization vulnerabilities
- History of Cross-Site Scripting vulnerabilities
Plugin Notes Plus Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Plugin Notes Plus <= 1.2.7 - Authenticated (Subscriber+) Arbitrary Note Deletion
Plugin Notes Plus <= 1.2.6 - Authenticated (Administrator+) Stored Cross-Site Scripting
Plugin Notes Plus Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Plugin Notes Plus Attack Surface
AJAX Handlers 2
WordPress Hooks 9
Maintenance & Trust
Plugin Notes Plus Maintenance & Trust
Maintenance Signals
Community Trust
Plugin Notes Plus Alternatives
Plugin Notes
plugin-notes
Allows you to add notes to plugins.
Plugin Notes Label
plugin-notes-label
Add your Notes to each plugin.
WP Rollback – Rollback Plugins and Themes
wp-rollback
Rollback (or forward) any WordPress.org plugin, theme, or block like a boss.
Download Plugin
download-plugin
Download any plugin from your WordPress admin panel's Plugins page by just one click! Now, download themes, users, blog posts, pages, custom post …
Advanced Automatic Updates
automatic-updater
Adds extra options to WordPress' built-in Automatic Updates feature.
Plugin Notes Plus Developer Profile
1 plugin · 9K total installs
How We Detect Plugin Notes Plus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/plugin-notes-plus/admin/css/plugin-notes-plus-admin.css/wp-content/plugins/plugin-notes-plus/admin/js/plugin-notes-plus-admin.js/wp-content/plugins/plugin-notes-plus/admin/js/plugin-notes-plus-updates.js/wp-content/plugins/plugin-notes-plus/admin/js/plugin-notes-plus-admin.js/wp-content/plugins/plugin-notes-plus/admin/js/plugin-notes-plus-updates.jsplugin-notes-plus/admin/css/plugin-notes-plus-admin.css?ver=plugin-notes-plus/admin/js/plugin-notes-plus-admin.js?ver=plugin-notes-plus/admin/js/plugin-notes-plus-updates.js?ver=HTML / DOM Fingerprints
<!-- Note: plugin-notes-plus -->data-plugin-notes-pluspnp_paramsupdateslabels