
Shortnotes Security & Risk Analysis
wordpress.org/plugins/shortnotesAdd a notes post type to WordPress. For your short notes.
Is Shortnotes Safe to Use in 2026?
Generally Safe
Score 100/100Shortnotes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "shortnotes" plugin v1.7.0 exhibits a generally good security posture based on the provided static analysis and vulnerability history. There are no identified critical or high-severity vulnerabilities from taint analysis, and the plugin does not appear to have any known exploitable CVEs. The use of prepared statements for all SQL queries and the absence of file operations are positive indicators of secure coding practices. However, several areas raise concerns that could be exploited. The complete absence of capability checks and nonce checks is a significant weakness, especially since there are AJAX handlers and cron events that could potentially be triggered by unauthenticated or low-privileged users. While the static analysis found no directly exploitable paths in taint analysis, the lack of robust authorization mechanisms means that even simple operations could be performed by unintended actors.
Although the plugin has no recorded vulnerability history, this does not guarantee future safety. The lack of authorization checks presents a substantial attack surface that could be leveraged for various malicious activities if specific code flaws exist but were not flagged by the static analysis. The external HTTP request also warrants attention, as it could be a vector for SSRF or data exfiltration if not properly secured. In conclusion, while "shortnotes" demonstrates strengths in SQL handling and a clean vulnerability record, the significant gaps in authorization and noncing represent a considerable risk that needs to be addressed to improve its overall security.
Key Concerns
- No capability checks found
- No nonce checks found
- 1 external HTTP request
- 1 cron event without auth checks
- One output not properly escaped
Shortnotes Security Vulnerabilities
Shortnotes Code Analysis
SQL Query Safety
Output Escaping
Shortnotes Attack Surface
WordPress Hooks 11
Scheduled Events 1
Maintenance & Trust
Shortnotes Maintenance & Trust
Maintenance Signals
Community Trust
Shortnotes Alternatives
Simple Footnotes
simple-footnotes
Create simple, elegant footnotes on your site. Use the [ref] shortcode and the plugin takes care of the rest.
IndieBlocks
indieblocks
Use blocks, and, optionally, "short-form" post types to easily "IndieWebify" your WordPress site.
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
MW WP Form
mw-wp-form
MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …
WebSub (FKA. PubSubHubbub)
pubsubhubbub
A WebSub plugin for WordPress that enables real-time publishing and subscription capabilities.
Shortnotes Developer Profile
5 plugins · 1K total installs
How We Detect Shortnotes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shortnotes/build/index.js/wp-content/plugins/shortnotes/build/index.jsshortnotes-extendedHTML / DOM Fingerprints
/wp-json/shortnotes/