
Sticky Notes for WP Dashboard Security & Risk Analysis
wordpress.org/plugins/wb-sticky-notesCreate sticky notes in your WP admin for reminders and to-dos. Restrict notes by user roles and disable them on specific pages.
Is Sticky Notes for WP Dashboard Safe to Use in 2026?
Generally Safe
Score 99/100Sticky Notes for WP Dashboard has a strong security track record. Known vulnerabilities have been patched promptly.
The wb-sticky-notes plugin v1.2.5 exhibits a mixed security posture. On the positive side, it demonstrates good practices in handling SQL queries and output escaping, with a high percentage of both using prepared statements and proper escaping, respectively. The absence of file operations and external HTTP requests is also a strength. However, there are significant concerns related to its attack surface. The presence of two AJAX handlers, one of which lacks authentication checks, is a critical vulnerability point. While taint analysis found no immediate critical or high-severity issues, the unchecked AJAX endpoint provides a clear entry point for potential exploitation.
The vulnerability history reveals one known medium-severity CVE, specifically related to missing authorization. This pattern, combined with the static analysis finding an unprotected AJAX handler, suggests a recurring weakness in how the plugin handles user permissions and access control. The fact that this CVE is not currently unpatched is a positive sign, indicating the developer has addressed past issues. Nevertheless, the uncovered static analysis findings and historical trends necessitate caution. The plugin has a generally good foundation in core security practices but requires immediate attention to its authorization mechanisms for exposed entry points to mitigate identified risks.
Key Concerns
- Unprotected AJAX handler
- One medium severity CVE historically
Sticky Notes for WP Dashboard Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Sticky Notes for WP Dashboard <= 1.2.4 - Missing Authorization
Sticky Notes for WP Dashboard Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Sticky Notes for WP Dashboard Attack Surface
AJAX Handlers 2
WordPress Hooks 8
Maintenance & Trust
Sticky Notes for WP Dashboard Maintenance & Trust
Maintenance Signals
Community Trust
Sticky Notes for WP Dashboard Alternatives
Plugmint – Draggable Admin Notes
plugmint-draggable-notes
Create draggable admin notes with checklists inside your WordPress dashboard. Easily organize important tasks or reminders.
A Note Above – WP Dashboard Notes
a-note-above-wp-dashboard-notes
A WordPress Note taking system to live on your WP Admin dashboard.
T4P Dashboard Notes
t4p-dashboard-notes
Add colored, formatted dashboard notes with titles and drag-and-drop widgets for internal admin documentation and reminders.
NoteFlow – Smart Notes Manager for WordPress Admin
noteflow
A simple and efficient notes manager for WordPress admin dashboard. Create, organize, and manage your notes directly from WordPress.
Ultimate Sticky Notes
ultimate-sticky-notes
The Ultimate Sticky Notes plugin offers the create, organize, and customize notes on your admin panel.
Sticky Notes for WP Dashboard Developer Profile
3 plugins · 11K total installs
How We Detect Sticky Notes for WP Dashboard
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wb-sticky-notes/admin/css/wb-sticky-notes-admin.css/wp-content/plugins/wb-sticky-notes/admin/css/select2.min.css/wp-content/plugins/wb-sticky-notes/admin/js/wb-sticky-notes-admin.js/wp-content/plugins/wb-sticky-notes/admin/js/select2.min.jswb-sticky-notes/admin/css/wb-sticky-notes-admin.css?ver=wb-sticky-notes/admin/css/select2.min.css?ver=wb-sticky-notes/admin/js/wb-sticky-notes-admin.js?ver=wb-sticky-notes/admin/js/select2.min.js?ver=HTML / DOM Fingerprints
wb_stn_newwb_stn_toggledata-wb-stn-plugin-urlwb_stn_data