Secret Placeholders
Embed password-manager secrets in notes as placeholders so the .md never contains the actual credential. Supports OpenBao/Vault, 1Password Connect, and Bitwarden/Vaultwarden. - This plugin has not been manually reviewed by Obsidian staff.
The above warnings are based on limited information and might not always be accurate.
Data
| ID | secret-placeholders |
| Author | Liam |
| Minimum Obsidian Version | 1.7.2 |
| Official Release Date | 2026-05-22 |
| Last update | 2026-07-07 |
Last Refresh
Obsidian Stats last refreshed the data behind this page on Jul 13, 2026.
| Community plugin snapshot | Jul 13, 2026 |
| Repository clone | last successful checkout Jul 7, 2026 |
| Release acquisition | release metadata checked Jul 7, 2026; latest main.js acquired |
Quick Links
Changes
| Date | Changed Property | Old Value | New Value |
|---|---|---|---|
| 2026-05-22 | Plugin Added | ||
| 2026-06-03 | author | lai2301 | Liam |
| 2026-06-15 | description | This plugin has not been manually reviewed by Obsidian staff. Embed password-manager secrets in notes as placeholders so the .md never contains the actual credential. Supports OpenBao/Vault, 1Password Connect, and Bitwarden/Vaultwarden. | Embed password-manager secrets in notes as placeholders so the .md never contains the actual credential. Supports OpenBao/Vault, 1Password Connect, and Bitwarden/Vaultwarden. - This plugin has not been manually reviewed by Obsidian staff. |
| 2026-07-06 | Plugin Removed | ||
| 2026-07-07 | Plugin Re-Added |
Repository Data
| License | MIT in package.json MIT in LICENSE file |
| Package Manager | npm |
| Uses Typescript | Yes |
| Installed Bundlers | esbuild |
| Installed Testing Frameworks | None found |
| Has Test Files | No |
Latest Release main.js Size | 376 KB |
| Detected ES Version | ES2020 |
| Probably Minified | Yes |
| main.js API Findings | 12 disclosures |
| Uses BRAT beta releases | No |
| Dependencies | hash-wasm |
| Dev Dependencies | @codemirror/state, @codemirror/view, @types/node, esbuild, eslint, eslint-plugin-obsidianmd, obsidian, tslib, typescript, typescript-eslint |
main.js API Findings
These conservative findings come from static analysis of the latest release main.js. The table includes warnings and high-confidence informational findings; lower-confidence informational findings are omitted to reduce false positives. Warnings indicate usage of potentially risky APIs, but such APIs can be used safely if handled with care.
| Disclosure | Detected From |
|---|---|
| Clipboard Access | Reads or writes clipboard data |
| Cors Free Network Access | Uses Obsidian request APIs |
| Editor Behavior | Registers editor extensions |
| Embedded Base64 Blob | Includes large embedded base64 blobs |
| Full Vault Access | Enumerates vault files |
| Global Handlers Or Timers | Registers events, DOM handlers, or intervals |
| Markdown Processing | Registers markdown processors or renderers |
| Network Access | Uses Obsidian request APIs |
| Note Content Access | Reads vault files |
| Private Network Access | References localhost or private-network addresses |
| Webassembly Usage | Uses WebAssembly APIs |
| Workspace Layout | Registers or manipulates workspace views and panes |
| Finding | Type | Confidence | Evidence |
|---|---|---|---|
| References localhost or private-network addresses | Warning | Medium | 127.0.0.1 (2), localhost (2) |
| Reads or writes clipboard data | Info | High | navigator.clipboard.writeText (4) |
| Uses persistent browser storage | Info | High | caches (4), localStorage (1) |
| Uses WebAssembly APIs | Info | High | WebAssembly (2) |
| Includes large embedded base64 blobs | Info | High | base64 blob (22) |
| Registers editor extensions | Info | High | this.registerEditorExtension (1) |
| Registers markdown processors or renderers | Info | High | this.registerMarkdownPostProcessor (1) |
| Registers events, DOM handlers, or intervals | Info | High | this.registerEvent (4) |
| References URLs or constructs URL objects | Info | High | http:// (2), https:// (9), URL (1), URLSearchParams (3) |
| Uses Obsidian request APIs | Info | High | obsidian.requestUrl (8) |
| Persists plugin settings or data | Info | High | this.loadData (1), this.saveData (1) |
| Registers plugin settings UI | Info | High | this.addSettingTab (1), Setting (37), obsidian.Setting (37) |
| Registers commands, ribbon icons, or status bar items | Info | High | this.addCommand (1), this.addRibbonIcon (1) |
| Accesses Obsidian vault APIs | Info | High | app.vault (6) |
| Enumerates vault files | Info | High | app.vault.getMarkdownFiles (1) |
| Reads vault files | Info | High | app.vault.cachedRead (1) |
| Accesses Obsidian workspace APIs | Info | High | app.workspace (1) |
| Registers or manipulates workspace views and panes | Info | High | registerView (1) |
The above data may not be accurate and contain errors. For more information refer to the page about data collection.
Lines of Code
The plugin has a total of 6292 lines of code. The following chart shows the lines of code split by programming language.
Downloads
The following chart shows the total number of downloads of the plugin over time. The second chart shows the delta of downloads per week, which is the number of new downloads per week. New version releases are marked with vertical lines.
Version History
| Version | Release Date | Note |
|---|---|---|
| 0.5.5 | 2026-05-21 | Released while not listed |
| 0.6.0 | 2026-05-22 | None |
| 0.6.1 | 2026-06-03 | None |
| 0.7.0 | 2026-07-05 | None |
| 0.7.1 | 2026-07-07 | None |
| 0.7.2 | 2026-07-07 | None |
Blacklisted versions are versions that are known to cause major issues or contain security concerns and have thus been blacklisted by the Obsidian team. Obsidian will disable plugins on startup whose installed version is blacklisted. Released while not listed versions happened outside the period where the plugin was present in the community plugin list and are excluded from aggregate release statistics.