
ST Admin Notes Security & Risk Analysis
wordpress.org/plugins/st-admin-notesA lightweight draggable admin notes plugin that lets you create sticky notes directly in the WordPress admin area.
Is ST Admin Notes Safe to Use in 2026?
Generally Safe
Score 100/100ST Admin Notes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The st-admin-notes plugin version 1.0.0 exhibits a mixed security posture. On the positive side, the code demonstrates strong adherence to secure coding practices regarding SQL queries, ensuring all are properly prepared, and all output is correctly escaped. Furthermore, there are no recorded vulnerabilities (CVEs) or past security incidents, suggesting a historically stable plugin. However, a significant concern arises from the attack surface analysis. The plugin exposes 5 AJAX handlers, all of which are missing authentication checks. This creates a direct and critical pathway for unauthenticated users to interact with potentially sensitive functionalities. While taint analysis shows no immediate issues, the unprotected AJAX endpoints represent a substantial risk that could be exploited if any of these handlers are susceptible to manipulation. The presence of nonce checks and capability checks on some functions is a positive indicator, but their absence on all AJAX handlers negates much of this benefit. The plugin would significantly improve its security by implementing proper authentication and authorization on all AJAX endpoints.
Key Concerns
- AJAX handlers without authentication checks
- Large attack surface from unprotected AJAX handlers
ST Admin Notes Security Vulnerabilities
ST Admin Notes Release Timeline
ST Admin Notes Code Analysis
Output Escaping
ST Admin Notes Attack Surface
AJAX Handlers 5
WordPress Hooks 6
Maintenance & Trust
ST Admin Notes Maintenance & Trust
Maintenance Signals
Community Trust
ST Admin Notes Alternatives
Sticky Notes for WP Dashboard
wb-sticky-notes
Create sticky notes in your WP admin for reminders and to-dos. Restrict notes by user roles and disable them on specific pages.
Noted!
noted
A simple, lightweight, and user-friendly note-taking system within the WordPress admin.
Custom Sticky Notes
custom-sticky-notes
Add simple sticky notes in the WordPress admin bar.
T4P Dashboard Notes
t4p-dashboard-notes
Add colored, formatted dashboard notes with titles and drag-and-drop widgets for internal admin documentation and reminders.
AdminHero
admin-hero
Admin notes for website administrators, accessible via a modal that lets you write, edit, and save notes directly within the WordPress dashboard.
ST Admin Notes Developer Profile
2 plugins · 0 total installs
How We Detect ST Admin Notes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/st-admin-notes/admin/css/st-admin-notes-admin.css/wp-content/plugins/st-admin-notes/admin/js/st-admin-notes-admin.jsst-admin-notes-admin.css?ver=st-admin-notes-admin.js?ver=HTML / DOM Fingerprints
st-notes-admin-carddata-stn-iddata-stn-colordata-stn-titledata-stn-contentdata-stn-activedata-stn-pos-x+4 morest_admin_notes_data