
Super annotation Security & Risk Analysis
wordpress.org/plugins/super-annotationAllows to add an extra column on the plugin page to quickly add a note in front of each plugin.
Is Super annotation Safe to Use in 2026?
Generally Safe
Score 92/100Super annotation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "super-annotation" plugin version 1.0.4 exhibits a generally positive security posture based on the static analysis. There are no identified dangerous functions, SQL queries are exclusively using prepared statements, and a high percentage of output is properly escaped. Furthermore, the plugin has no recorded vulnerability history, suggesting a strong track record of secure development. The attack surface is also commendably small, with no public entry points like AJAX handlers, REST API routes, or shortcodes that lack authentication checks.
However, a significant concern arises from the taint analysis, which revealed two flows with unsanitized paths. While these did not escalate to critical or high severity, the presence of unsanitized paths indicates a potential for vulnerabilities if data originating from these flows were to be used in a sensitive operation, such as file access or command execution, without proper sanitization. The complete absence of nonce checks and capability checks across all entry points (though the entry points are zero) is also a notable omission that could become a risk if new entry points were introduced without these security measures.
In conclusion, "super-annotation" v1.0.4 is built on a foundation of good security practices, particularly in its handling of SQL and output. The lack of historical vulnerabilities is a strong positive indicator. The primary weakness lies in the identified unsanitized taint flows, which, while not currently exploited, represent a latent risk that warrants attention and mitigation.
Key Concerns
- Taint flows with unsanitized paths found
- No nonce checks implemented
- No capability checks implemented
Super annotation Security Vulnerabilities
Super annotation Code Analysis
Output Escaping
Data Flow Analysis
Super annotation Attack Surface
WordPress Hooks 6
Maintenance & Trust
Super annotation Maintenance & Trust
Maintenance Signals
Community Trust
Super annotation Alternatives
No alternatives data available yet.
Super annotation Developer Profile
2 plugins · 30 total installs
How We Detect Super annotation
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
extension-annotation-textareacolumn-extension_annotationssaved_annotationscolumn-saved_annotationsactivename="extension_annotationsvalue="document.getElementsByName