User Notes Security & Risk Analysis

wordpress.org/plugins/user-notes

Keep private notes about each of your users that only Administrators can see.

900 active installs v2.0.0 PHP + WP 6.0+ Updated Apr 12, 2026
admin-notesnoteprivate-notessecure-notesuser
98
A · Safe
CVEs total2
Unpatched0
Last CVESep 26, 2025
Safety Verdict

Is User Notes Safe to Use in 2026?

Generally Safe

Score 98/100

User Notes has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

2 known CVEsLast CVE: Sep 26, 2025Updated 1mo ago
Risk Assessment

The "user-notes" v1.0.4 plugin exhibits a strong security posture based on static analysis, with no identified vulnerabilities in attack surface, dangerous functions, raw SQL queries, unescaped output, file operations, or external HTTP requests. The presence of nonce and capability checks further strengthens its defensive mechanisms. Taint analysis also revealed no critical or high severity vulnerabilities, indicating robust input sanitization and handling within the analyzed code flows.

However, the plugin's vulnerability history presents a significant concern. With two known medium-severity CVEs, both of which have been addressed according to the data, it suggests a past pattern of security weaknesses. The historical prevalence of Cross-site Scripting (XSS) vulnerabilities, even if patched, indicates a need for continued vigilance. While the current version appears secure based on static analysis, past issues warrant a cautious approach and underscore the importance of timely updates.

In conclusion, "user-notes" v1.0.4 demonstrates excellent static security characteristics, aligning with best practices for secure WordPress plugin development. The absence of immediate threats from the code analysis is commendable. Nevertheless, the historical track record of medium-severity XSS vulnerabilities necessitates a careful evaluation and ongoing monitoring to ensure that past weaknesses do not resurface.

Key Concerns

  • Past medium severity XSS vulnerabilities
Vulnerabilities
2 published

User Notes Security Vulnerabilities

CVEs by Year

1 CVE in 2021
2021
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-60136medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

User Notes <= 1.0.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

Sep 26, 2025 Patched in 1.0.3 (154d)
WF-f5bdf47a-1116-4d3a-8ded-89d76b5a6f82-user-notesmedium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

User Notes <= 1.0.1 - Cross-Site Scripting

Apr 12, 2021 Patched in 1.0.2 (1016d)
Version History

User Notes Release Timeline

Code Analysis
Analyzed Mar 16, 2026

User Notes Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
14 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped14 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
user_notes_display_column (user-notes.php:78)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

User Notes Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionshow_user_profileuser-notes.php:52
actionedit_user_profileuser-notes.php:53
actionpersonal_options_updateuser-notes.php:68
actionedit_user_profile_updateuser-notes.php:69
filtermanage_users_columnsuser-notes.php:76
actionmanage_users_custom_columnuser-notes.php:111
actionadmin_enqueue_scriptsuser-notes.php:120
Maintenance & Trust

User Notes Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 12, 2026
PHP min version
Downloads15K

Community Trust

Rating96/100
Number of ratings15
Active installs900
Developer Profile

User Notes Developer Profile

cartpauj

6 plugins · 32K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
1225 days
View full developer profile
Detection Fingerprints

How We Detect User Notes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
user_notes_thickbox
Data Attributes
id="user_notes_thickbox_"inlineId=user_notes_thickbox_
FAQ

Frequently Asked Questions about User Notes