
Sticky Notes for WP Dashboard Security & Risk Analysis
wordpress.org/plugins/wb-sticky-notesCreate sticky notes in your WP admin for reminders and to-dos. Restrict notes by user roles and disable them on specific pages.
Is Sticky Notes for WP Dashboard Safe to Use in 2026?
Generally Safe
Score 99/100Sticky Notes for WP Dashboard has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The wb-sticky-notes plugin v1.2.5 exhibits a mixed security posture. On the positive side, it demonstrates good practices in handling SQL queries and output escaping, with a high percentage of both using prepared statements and proper escaping, respectively. The absence of file operations and external HTTP requests is also a strength. However, there are significant concerns related to its attack surface. The presence of two AJAX handlers, one of which lacks authentication checks, is a critical vulnerability point. While taint analysis found no immediate critical or high-severity issues, the unchecked AJAX endpoint provides a clear entry point for potential exploitation.
The vulnerability history reveals one known medium-severity CVE, specifically related to missing authorization. This pattern, combined with the static analysis finding an unprotected AJAX handler, suggests a recurring weakness in how the plugin handles user permissions and access control. The fact that this CVE is not currently unpatched is a positive sign, indicating the developer has addressed past issues. Nevertheless, the uncovered static analysis findings and historical trends necessitate caution. The plugin has a generally good foundation in core security practices but requires immediate attention to its authorization mechanisms for exposed entry points to mitigate identified risks.
Key Concerns
- Unprotected AJAX handler
- One medium severity CVE historically
Sticky Notes for WP Dashboard Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Sticky Notes for WP Dashboard <= 1.2.4 - Missing Authorization
Sticky Notes for WP Dashboard Release Timeline
Sticky Notes for WP Dashboard Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Sticky Notes for WP Dashboard Attack Surface
AJAX Handlers 2
WordPress Hooks 8
Maintenance & Trust
Sticky Notes for WP Dashboard Maintenance & Trust
Maintenance Signals
Community Trust
Sticky Notes for WP Dashboard Alternatives
Plugmint – Draggable Admin Notes
plugmint-draggable-notes
Create draggable admin notes with checklists inside your WordPress dashboard. Easily organize important tasks or reminders.
A Note Above – WP Dashboard Notes
a-note-above-wp-dashboard-notes
A WordPress Note taking system to live on your WP Admin dashboard.
NoteFlow – Smart Notes Manager for WordPress Admin
noteflow
A simple and efficient notes manager for WordPress admin dashboard. Create, organize, and manage your notes directly from WordPress.
T4P Dashboard Notes
t4p-dashboard-notes
Add colored, formatted dashboard notes with titles and drag-and-drop widgets for internal admin documentation and reminders.
KeepInMind Dashboard Notes
keepinmind-dashboard-notes
Leave contextual notes on any WordPress admin page. Pin notes to specific elements, collaborate with your team, and stay on top of admin tasks.
Sticky Notes for WP Dashboard Developer Profile
3 plugins · 11K total installs
How We Detect Sticky Notes for WP Dashboard
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wb-sticky-notes/admin/css/wb-sticky-notes-admin.css/wp-content/plugins/wb-sticky-notes/admin/css/select2.min.css/wp-content/plugins/wb-sticky-notes/admin/js/wb-sticky-notes-admin.js/wp-content/plugins/wb-sticky-notes/admin/js/select2.min.jswb-sticky-notes/admin/css/wb-sticky-notes-admin.css?ver=wb-sticky-notes/admin/css/select2.min.css?ver=wb-sticky-notes/admin/js/wb-sticky-notes-admin.js?ver=wb-sticky-notes/admin/js/select2.min.js?ver=HTML / DOM Fingerprints
wb_stn_newwb_stn_toggledata-wb-stn-plugin-urlwb_stn_data