
Tooltipy (tooltips for WP) Security & Risk Analysis
wordpress.org/plugins/bluet-keywords-tooltip-generatorTooltipy allows you to highlight the keywords in your content in order to show a responsive description tooltips
Is Tooltipy (tooltips for WP) Safe to Use in 2026?
Mostly Safe
Score 74/100Tooltipy (tooltips for WP) is generally safe to use. 4 past CVEs were resolved. Keep it updated.
The bluet-keywords-tooltip-generator plugin version 5.5.9 presents a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its SQL queries and implementing nonce and capability checks for its entry points, indicating a conscious effort to prevent common web vulnerabilities. The absence of file operations and external HTTP requests further limits the potential attack surface in these areas.
However, several concerns warrant attention. The static analysis reveals a significant portion of output is not properly escaped (43% properly escaped), which could lead to Cross-Site Scripting (XSS) vulnerabilities if unsanitized user input reaches these outputs. Furthermore, the taint analysis indicates two flows with unsanitized paths, both flagged as high severity, suggesting potential vulnerabilities where untrusted data could be used in a way that compromises security. The plugin's history of four known CVEs, with one currently unpatched, is a significant red flag, especially given that past vulnerabilities have included CSRF and XSS. This historical pattern, combined with the current taint analysis findings, suggests a recurring weakness in input sanitization and output encoding.
In conclusion, while the plugin implements some fundamental security controls, the prevalence of unescaped output, the high-severity taint flows, and the concerning vulnerability history, particularly the unpatched CVE, indicate a need for immediate review and remediation to improve its overall security. The lack of proper output escaping and the identified unsanitized taint flows are the most pressing concerns.
Key Concerns
- Unpatched CVE
- High severity taint flow
- High severity taint flow
- Low percentage of properly escaped output
Tooltipy (tooltips for WP) Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Tooltipy <= 5.5.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Tooltipy <= 5.5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
Tooltipy < 5.1 - Cross-Site Request Forgery
Tooltipy (tooltips for WP) <= 5.0 - Reflected Cross-Site Scripting
Tooltipy (tooltips for WP) Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Tooltipy (tooltips for WP) Attack Surface
AJAX Handlers 2
Shortcodes 3
WordPress Hooks 45
Maintenance & Trust
Tooltipy (tooltips for WP) Maintenance & Trust
Maintenance Signals
Community Trust
Tooltipy (tooltips for WP) Alternatives
CM Tooltip Glossary
enhanced-tooltipglossary
Transform jargon into engaging content that boosts SEO, drives engagement, improves conversions, with automatic links and tooltips.
Tooltips for WordPress
wordpress-tooltips
Add custom tooltip automatically for post's content/title/tag/excerpt/gallery/menu, easily add image / video / audio / social/link tooltips
Glossary
glossary-by-codeat
Boost your SEO & UX with Codeat's Glossary: powerful auto-link engine; customizable tooltips, mobile settings, ChatGPT and much more!
Simple Keyword to Link
simple-keyword-to-link
Really Simple "Keyword to Link" Converter. Automatically create links for specific words in your content
Keywords to Links Converter
links-auto-replacer
Convert your post content keywords to Links automatically, Using the same links over and over again in your posts? This is the solution.
Tooltipy (tooltips for WP) Developer Profile
4 plugins · 1K total installs
How We Detect Tooltipy (tooltips for WP)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bluet-keywords-tooltip-generator/library/findandreplacedomtext.jsbluet-keywords-tooltip-generator/style.css?ver=bluet-keywords-tooltip-generator/advanced/advanced.css?ver=bluet-keywords-tooltip-generator/advanced/advanced.js?ver=bluet-keywords-tooltip-generator/assets/css/tooltipy-free.css?ver=bluet-keywords-tooltip-generator/assets/js/tooltipy-free.js?ver=bluet-keywords-tooltip-generator/assets/js/tooltipy-tooltip.js?ver=HTML / DOM Fingerprints
tooltipy-kw-cat-tooltipy-kw-cat-bluet_exclude_post_from_matchingbluet_exclude_keywords_from_matchingbt_kw_positionbt_kw_animation_typebt_kw_animation_speedbluet_case_sensitive_word+5 moretooltipy_post_type_nametooltip_post_typesbluet_kw_settingstooltipy_keywords_titles_idsanimation_typeanimation_speed