Sticky Notes Widget Security & Risk Analysis

wordpress.org/plugins/sticky-notes-widget

A plugin for adding sticky notes on the widget area!

70 active installs v1.0.1 PHP + WP 3.5+ Updated Feb 20, 2015
notespaperstickytextswidgets
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sticky Notes Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Sticky Notes Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The sticky-notes-widget plugin v1.0.1 demonstrates a generally good security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code signals indicate no dangerous functions, no file operations, and no external HTTP requests, all of which are positive security indicators. The use of prepared statements for all SQL queries is also a strong defense against SQL injection vulnerabilities.

Key Concerns

  • Low output escaping coverage
  • No capability checks on entry points
  • No nonce checks on potential entry points
Vulnerabilities
None known

Sticky Notes Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Sticky Notes Widget Release Timeline

v1.0.1Current
v1.0
Code Analysis
Analyzed Apr 16, 2026

Sticky Notes Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
37
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

21% escaped47 total outputs
Attack Surface

Sticky Notes Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwidgets_initsticky-notes-widget.php:148
actionadmin_enqueue_scriptssticky-notes-widget.php:157
actionwp_enqueue_scriptssticky-notes-widget.php:164
Maintenance & Trust

Sticky Notes Widget Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedFeb 20, 2015
PHP min version
Downloads5K

Community Trust

Rating96/100
Number of ratings4
Active installs70
Developer Profile

Sticky Notes Widget Developer Profile

Nazmul Hossain Nihal

5 plugins · 200 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sticky Notes Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sticky-notes-widget/sticky-notes-fonts.css/wp-content/plugins/sticky-notes-widget/sticky-notes-styles.css
Script Paths
/wp-content/plugins/sticky-notes-widget/js/jscolor.js
Version Parameters
sticky-notes-widget/sticky-notes-fonts.css?ver=sticky-notes-widget/sticky-notes-styles.css?ver=

HTML / DOM Fingerprints

CSS Classes
snw-boxtapingpaper
Data Attributes
snw-color-picker
JS Globals
jscolor
FAQ

Frequently Asked Questions about Sticky Notes Widget