
Tooltipy (tooltips for WP) Security & Risk Analysis
wordpress.org/plugins/bluet-keywords-tooltip-generatorAutomatically add customizable keyword tooltips to your content and boost SEO, UX, and engagement — no coding required.
Is Tooltipy (tooltips for WP) Safe to Use in 2026?
Mostly Safe
Score 74/100Tooltipy (tooltips for WP) is generally safe to use. 4 past CVEs were resolved.
The bluet-keywords-tooltip-generator plugin version 5.5.9 presents a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its SQL queries and implementing nonce and capability checks for its entry points, indicating a conscious effort to prevent common web vulnerabilities. The absence of file operations and external HTTP requests further limits the potential attack surface in these areas.
However, several concerns warrant attention. The static analysis reveals a significant portion of output is not properly escaped (43% properly escaped), which could lead to Cross-Site Scripting (XSS) vulnerabilities if unsanitized user input reaches these outputs. Furthermore, the taint analysis indicates two flows with unsanitized paths, both flagged as high severity, suggesting potential vulnerabilities where untrusted data could be used in a way that compromises security. The plugin's history of four known CVEs, with one currently unpatched, is a significant red flag, especially given that past vulnerabilities have included CSRF and XSS. This historical pattern, combined with the current taint analysis findings, suggests a recurring weakness in input sanitization and output encoding.
In conclusion, while the plugin implements some fundamental security controls, the prevalence of unescaped output, the high-severity taint flows, and the concerning vulnerability history, particularly the unpatched CVE, indicate a need for immediate review and remediation to improve its overall security. The lack of proper output escaping and the identified unsanitized taint flows are the most pressing concerns.
Key Concerns
- Unpatched CVE
- High severity taint flow
- High severity taint flow
- Low percentage of properly escaped output
Tooltipy (tooltips for WP) Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Tooltipy <= 5.5.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Tooltipy <= 5.5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
Tooltipy < 5.1 - Cross-Site Request Forgery
Tooltipy (tooltips for WP) <= 5.0 - Reflected Cross-Site Scripting
Tooltipy (tooltips for WP) Release Timeline
Tooltipy (tooltips for WP) Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Tooltipy (tooltips for WP) Attack Surface
AJAX Handlers 2
Shortcodes 3
WordPress Hooks 45
Maintenance & Trust
Tooltipy (tooltips for WP) Maintenance & Trust
Maintenance Signals
Community Trust
Tooltipy (tooltips for WP) Alternatives
Eatransform Auto Keyword Linker
eatransform-auto-keyword-linker
Automatically convert keywords in your content into links. Simple, unlimited, and free.
Auto Internal Linking Optimizer
auto-internal-linking-optimizer
Automatically adds internal links to your posts and pages based on defined keywords to boost SEO.
Interlinko – Smart Internal Linking for WordPress
interlinko
Automatically converts keywords in your content into links. Simple, unlimited and SEO-optimized.
Link Whisper Free
link-whisper
The AI-powered internal linking plugin for WordPress. Build internal links faster, find linking opportunities, and improve SEO automatically.
Simple SEO
cds-simple-seo
Allows the modification of META titles, descriptions and keywords for all pages and posts. Also allows for default setting for of META title, descript …
Tooltipy (tooltips for WP) Developer Profile
4 plugins · 1K total installs
How We Detect Tooltipy (tooltips for WP)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bluet-keywords-tooltip-generator/library/findandreplacedomtext.jsbluet-keywords-tooltip-generator/style.css?ver=bluet-keywords-tooltip-generator/advanced/advanced.css?ver=bluet-keywords-tooltip-generator/advanced/advanced.js?ver=bluet-keywords-tooltip-generator/assets/css/tooltipy-free.css?ver=bluet-keywords-tooltip-generator/assets/js/tooltipy-free.js?ver=bluet-keywords-tooltip-generator/assets/js/tooltipy-tooltip.js?ver=HTML / DOM Fingerprints
tooltipy-kw-cat-tooltipy-kw-cat-bluet_exclude_post_from_matchingbluet_exclude_keywords_from_matchingbt_kw_positionbt_kw_animation_typebt_kw_animation_speedbluet_case_sensitive_word+5 moretooltipy_post_type_nametooltip_post_typesbluet_kw_settingstooltipy_keywords_titles_idsanimation_typeanimation_speed