
Simple Post Notes Security & Risk Analysis
wordpress.org/plugins/simple-post-notesAdds simple notes to post, page and custom post type edit screen.
Is Simple Post Notes Safe to Use in 2026?
Generally Safe
Score 98/100Simple Post Notes has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of simple-post-notes v1.8.1 reveals a generally good security posture with several strong practices in place. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. The plugin also demonstrates robust use of nonces and capability checks for its entry points, and importantly, the taint analysis found no vulnerabilities. However, the vulnerability history presents a significant concern. The plugin has had three documented medium-severity vulnerabilities, including CSRF and XSS. While there are currently no unpatched vulnerabilities, the recurring nature of these issues suggests a pattern of introducing flaws that require patching, indicating potential weaknesses in the development or review process.
The primary risk lies not in the current code's direct entry points, which appear protected, but in the historical tendency for vulnerabilities to emerge. The past medium-severity XSS and CSRF issues, even if patched, highlight potential areas where input validation or output escaping might be insufficient in certain contexts or future updates. The high percentage of properly escaped outputs (87%) is positive, but the remaining 13% could still be a vector for the types of XSS vulnerabilities seen historically. While the plugin has strengths in its modern coding practices, the vulnerability history necessitates vigilance and suggests that ongoing security audits and thorough testing are crucial to prevent future occurrences of similar issues.
Key Concerns
- Historical medium severity vulnerabilities (3)
- 13% of outputs not properly escaped
Simple Post Notes Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Simple Post Notes <= 1.7.7 - Authenticated (Administrator+) Stored Cross-Site Scripting
Simple Post Notes <= 1.7.6 - Cross-Site Request Forgery
Simple Post Notes <= 1.7.5 - Subscriber+ Stored Cross-Site Scripting
Simple Post Notes Code Analysis
Bundled Libraries
Output Escaping
Simple Post Notes Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
Simple Post Notes Maintenance & Trust
Maintenance Signals
Community Trust
Simple Post Notes Alternatives
Plugmint – Sticky Notes for Posts, Pages, Products & CPTs
plugmint-sticky-notes
A lightweight plugin to add private admin-only notes to posts, pages, products and on any custom post types.
Page & Post Notes
page-post-notes
Simple plugin that allow you to notes on pages and posts
Notely
notely
Create admin text notes for any post, page or custom post type.
Beckin Post Notes
beckin-post-notes
Add private admin notes to posts, pages, and custom post types - simple, fast, and clutter-free.
Admin Backend Color Coded Post Notes
admin-backend-color-coded-post-notes
Allows administrators to leave color-coded notes on posts and pages within the editor, ensuring clear and organized communication.
Simple Post Notes Developer Profile
9 plugins · 51K total installs
How We Detect Simple Post Notes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-post-notes/css/simple-post-notes.css/wp-content/plugins/simple-post-notes/js/simple-post-notes.jssimple-post-notes/css/simple-post-notes.css?ver=simple-post-notes/js/simple-post-notes.js?ver=HTML / DOM Fingerprints
inline-edit-col-rightinline-edit-groupspnote-name="spnote"placeholder[spnote]