WP Evernote Site Memory Security & Risk Analysis

wordpress.org/plugins/wp-evernote-site-memory

WP Evernote Site Memory fully integrates Evernote's Site Memory feature into your Wordpress blog.

30 active installs v2.0.2 PHP + WP 2.7+ Updated Nov 28, 2012
clippingevernotesite-memory
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Evernote Site Memory Safe to Use in 2026?

Generally Safe

Score 85/100

WP Evernote Site Memory has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "wp-evernote-site-memory" plugin, version 2.0.2, exhibits a strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events means a very limited attack surface, and crucially, no unprotected entry points were identified. The code also demonstrates good practices with no dangerous functions, no raw SQL queries (all using prepared statements), and no file operations or external HTTP requests. The presence of capability checks is a positive sign for authorization. However, the relatively low percentage of properly escaped output (67%) is a notable concern, suggesting a potential for cross-site scripting (XSS) vulnerabilities, although no specific flows were flagged by the taint analysis.

Key Concerns

  • Output escaping is not consistently applied
Vulnerabilities
None known

WP Evernote Site Memory Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WP Evernote Site Memory Release Timeline

v2.0.2Current
v2.0.1
v2.0
v1.1.1
v1.1
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0
Code Analysis
Analyzed Mar 16, 2026

WP Evernote Site Memory Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
20 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped30 total outputs
Attack Surface

WP Evernote Site Memory Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionwp_enqueue_scriptsevernote-site-memory.php:50
actionwp_enqueue_scriptsevernote-site-memory.php:51
actionadmin_enqueue_scriptsevernote-site-memory.php:53
actionadmin_menuevernote-site-memory.php:54
actionadmin_menuevernote-site-memory.php:55
filterthe_contentevernote-site-memory.php:58
filterthe_excerptevernote-site-memory.php:59
Maintenance & Trust

WP Evernote Site Memory Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedNov 28, 2012
PHP min version
Downloads15K

Community Trust

Rating100/100
Number of ratings1
Active installs30
Developer Profile

WP Evernote Site Memory Developer Profile

Jonathan Desrosiers

9 plugins · 21K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Evernote Site Memory

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-evernote-site-memory/css/styles.css/wp-content/plugins/wp-evernote-site-memory/css/admin.css
Script Paths
http://static.evernote.com/noteit.min.jshttp://static.evernote.com/noteit.js
Version Parameters
wp-evernote-site-memory/css/styles.css?ver=wp-evernote-site-memory/css/admin.css?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Evernote Site Memory -->
Data Attributes
data-evernote-urldata-evernote-sourcedata-evernote-titledata-evernote-contentdata-evernote-related
FAQ

Frequently Asked Questions about WP Evernote Site Memory