
Plugmint – Draggable Admin Notes Security & Risk Analysis
wordpress.org/plugins/plugmint-draggable-notesCreate draggable admin notes with checklists inside your WordPress dashboard. Easily organize important tasks or reminders.
Is Plugmint – Draggable Admin Notes Safe to Use in 2026?
Generally Safe
Score 100/100Plugmint – Draggable Admin Notes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "plugmint-draggable-notes" v1.0.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its SQL queries and properly escaping a very high percentage of its output. Furthermore, there are no recorded vulnerabilities (CVEs) for this plugin, suggesting a history of responsible development or limited exposure. The absence of dangerous functions, file operations, and external HTTP requests are also positive indicators.
However, the plugin's primary concern lies in its attack surface. With a total of 8 AJAX handlers, 3 of them are not protected by authentication checks. This creates a significant potential entry point for unauthenticated users to interact with the plugin's backend functionality, which could lead to unintended consequences or be chained with other potential weaknesses. While taint analysis found no issues, the unprotected AJAX handlers represent a concrete, evidence-backed risk that requires attention.
In conclusion, while "plugmint-draggable-notes" v1.0.0 has strong fundamentals in SQL and output handling, and a clean vulnerability history, the presence of unprotected AJAX endpoints is a notable weakness. Addressing these unprotected handlers should be the immediate priority to improve its overall security.
Key Concerns
- Unprotected AJAX handlers
Plugmint – Draggable Admin Notes Security Vulnerabilities
Plugmint – Draggable Admin Notes Release Timeline
Plugmint – Draggable Admin Notes Code Analysis
SQL Query Safety
Output Escaping
Plugmint – Draggable Admin Notes Attack Surface
AJAX Handlers 8
WordPress Hooks 7
Maintenance & Trust
Plugmint – Draggable Admin Notes Maintenance & Trust
Maintenance Signals
Community Trust
Plugmint – Draggable Admin Notes Alternatives
Sticky Notes for WP Dashboard
wb-sticky-notes
Create sticky notes in your WP admin for reminders and to-dos. Restrict notes by user roles and disable them on specific pages.
A Note Above – WP Dashboard Notes
a-note-above-wp-dashboard-notes
A WordPress Note taking system to live on your WP Admin dashboard.
WP Admin Todo List
wp-admin-todo-list
WP Admin Todo List helps you to keep list of the tasks in admin panel. It is helpful tool for developers, administrators and users as well.
NoteFlow – Smart Notes Manager for WordPress Admin
noteflow
A simple and efficient notes manager for WordPress admin dashboard. Create, organize, and manage your notes directly from WordPress.
T4P Dashboard Notes
t4p-dashboard-notes
Add colored, formatted dashboard notes with titles and drag-and-drop widgets for internal admin documentation and reminders.
Plugmint – Draggable Admin Notes Developer Profile
2 plugins · 0 total installs
How We Detect Plugmint – Draggable Admin Notes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/plugmint-draggable-notes/assets/css/admin-notes.css/wp-content/plugins/plugmint-draggable-notes/assets/js/admin-notes.js/wp-content/plugins/plugmint-draggable-notes/assets/js/admin-notes.jsplugmint-draggable-notes/assets/css/admin-notes.css?ver=plugmint-draggable-notes/assets/js/admin-notes.js?ver=HTML / DOM Fingerprints
admin-notes-wrapnotes-head-sectionadmin-notes-actionsadmin-notes-boardadmin-note-itemnote-headernote-titlenote-actions+12 more<!-- Tooltip user guide --><!-- All Notes -->data-note-iddata-note-orderdata-note-colordata-note-visibilitypdanAdminNotes