
WP Evernote Synchronizer Security & Risk Analysis
wordpress.org/plugins/wp-evernote-synchronizerEnables users to import Notes from Evernote Account.
Is WP Evernote Synchronizer Safe to Use in 2026?
Generally Safe
Score 85/100WP Evernote Synchronizer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-evernote-synchronizer plugin v1.0.7 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and incorporating nonce and capability checks in a significant number of its functions. The absence of known CVEs and the lack of recorded past vulnerabilities suggest a generally stable and secure history for this plugin. However, there are significant security concerns arising from the static analysis. A notable area of risk is the presence of two AJAX handlers that lack authentication checks, creating direct entry points for unauthenticated users. Additionally, the use of a dangerous function (preg_replace(/e)) and a low percentage of properly escaped outputs raise concerns about potential code injection or cross-site scripting (XSS) vulnerabilities, even though taint analysis did not reveal critical or high severity issues in the analyzed flows. The relatively small attack surface is a mitigating factor, but the unprotected entry points are a clear weakness.
Key Concerns
- Unprotected AJAX handlers
- Low percentage of properly escaped outputs
- Use of dangerous function (preg_replace(/e))
WP Evernote Synchronizer Security Vulnerabilities
WP Evernote Synchronizer Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
WP Evernote Synchronizer Attack Surface
AJAX Handlers 2
WordPress Hooks 10
Scheduled Events 2
Maintenance & Trust
WP Evernote Synchronizer Maintenance & Trust
Maintenance Signals
Community Trust
WP Evernote Synchronizer Alternatives
One Click Demo Import
one-click-demo-import
Import your demo content, widgets and theme settings with one click. Theme authors! Enable simple theme demo import for your users.
Rara One Click Demo Import
rara-one-click-demo-import
Make your website look like the live demo of the theme with a click!
AF Companion – Build Stylish WordPress Websites in Minutes – No Coding, Just Click and Go! Starter Sites Importer for WordPress
af-companion
Quickly import live demo content, widgets and settings with one click
Content Egg – Affiliate Product Importer & Price Comparison
content-egg
Import affiliate products, compare prices, sync to WooCommerce, and auto-generate SEO content with AI — all in one toolkit.
TutorMate
tutormate
TutorMate is a Tutor Starter theme companion plugin to import predesigned stylish demo pages to eLearning sites powered by Tutor LMS plugin.
WP Evernote Synchronizer Developer Profile
6 plugins · 230 total installs
How We Detect WP Evernote Synchronizer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-evernote-synchronizer/css/style.css/wp-content/plugins/wp-evernote-synchronizer/css/evernote-sync.css/wp-content/plugins/wp-evernote-synchronizer/js/evernote-sync.jswp-evernote-synchronizer/css/style.css?ver=wp-evernote-synchronizer/css/evernote-sync.css?ver=wp-evernote-synchronizer/js/evernote-sync.js?ver=HTML / DOM Fingerprints
wpes-evernote-settings-wrapdata-wpes-evernote-urlwpes_evernote_object