Image Hotspot by DevVN Security & Risk Analysis

wordpress.org/plugins/devvn-image-hotspot

Image Hotspot by DevVN helps you add hotspots to your images.

30K active installs v1.3.0 PHP + WP 4.6+ Updated Dec 11, 2025
hotspotimageimage-hotspotmapspoints
96
A · Safe
CVEs total2
Unpatched0
Last CVEFeb 18, 2026
Safety Verdict

Is Image Hotspot by DevVN Safe to Use in 2026?

Generally Safe

Score 96/100

Image Hotspot by DevVN has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Feb 18, 2026Updated 3mo ago
Risk Assessment

The devvn-image-hotspot plugin exhibits a mixed security posture. While it demonstrates good practices in several areas, including the complete use of prepared statements for SQL queries and a high percentage of properly escaped output, significant concerns remain. The presence of two instances of the dangerous `unserialize` function, especially without clear evidence of sanitization or input validation surrounding its usage, is a notable risk. Although taint analysis shows no identified flows with unsanitized paths, this could be a limitation of the analysis rather than a true absence of risk, particularly given the `unserialize` function.

The vulnerability history, with two known CVEs including one high and one medium severity vulnerability, points to past security weaknesses, specifically Cross-site Scripting and Code Injection. The fact that the last vulnerability was in 2026 suggests an effort to address past issues, but the existence of these vulnerabilities indicates a potential for similar issues to re-emerge if not carefully monitored and mitigated. The lack of currently unpatched vulnerabilities is a positive sign, but the historical pattern warrants caution.

In conclusion, while the plugin has strengths in its handling of SQL and output, the potential risks associated with `unserialize` and the historical pattern of vulnerabilities, particularly those related to input manipulation, necessitate careful review and potential patching. The limited attack surface and existing checks are positive, but the identified code signals and past CVEs suggest that vigilance is still required.

Key Concerns

  • Dangerous function unserialize present
  • High severity CVE in history
  • Medium severity CVE in history
Vulnerabilities
2

Image Hotspot by DevVN Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

High
1
Medium
1

2 total CVEs

CVE-2025-14445medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Image Hotspot by DevVN <= 1.2.9 - Authenticated (Author+) Stored Cross-Site Scripting via Custom Field Meta

Feb 18, 2026 Patched in 1.3.0 (1d)
CVE-2024-7656high · 8.8Improper Control of Generation of Code ('Code Injection')

Image Hotspot by DevVN <= 1.2.5 - Authenticated (Author+) PHP Object Injection

Aug 23, 2024 Patched in 1.2.6 (1d)
Code Analysis
Analyzed Mar 16, 2026

Image Hotspot by DevVN Code Analysis

Dangerous Functions
2
Raw SQL Queries
0
2 prepared
Unescaped Output
4
158 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$data_post = @unserialize( trim( $post_content ), array('allowed_classes' => false));admin\inc\add_shortcode_devvn_ihotspot.php:21
unserialize$data_post = @unserialize( trim( $post_content ), array('allowed_classes' => false));devvn-image-hotspot.php:119

SQL Query Safety

100% prepared2 total queries

Output Escaping

98% escaped162 total outputs
Attack Surface

Image Hotspot by DevVN Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_devvn_ihotspot_clone_pointdevvn-image-hotspot.php:680

Shortcodes 1

[devvn_ihotspot] admin\inc\add_shortcode_devvn_ihotspot.php:133
WordPress Hooks 19
actioninitadmin\inc\cpt-ihotspot.php:54
actionadmin_head-post-new.phpadmin\inc\cpt-ihotspot.php:65
actionadmin_head-post.phpadmin\inc\cpt-ihotspot.php:66
filterpage_row_actionsadmin\inc\cpt-ihotspot.php:69
filterpost_row_actionsadmin\inc\cpt-ihotspot.php:70
filtermanage_edit-points_image_columnsadmin\inc\cpt-ihotspot.php:89
actionmanage_points_image_posts_custom_columnadmin\inc\cpt-ihotspot.php:102
actionadd_meta_boxesadmin\inc\metabox-donate.php:18
actionadmin_initadmin\inc\settings.php:4
actionadmin_menuadmin\inc\settings.php:28
filterbody_classadmin\inc\settings.php:93
filterload_textdomain_mofiledevvn-image-hotspot.php:73
actionadd_meta_boxesdevvn-image-hotspot.php:99
filterwp_default_editordevvn-image-hotspot.php:106
actionsave_postdevvn-image-hotspot.php:441
actionadmin_enqueue_scriptsdevvn-image-hotspot.php:499
actionadmin_print_stylesdevvn-image-hotspot.php:509
actionwp_enqueue_scriptsdevvn-image-hotspot.php:524
filterwp_default_editordevvn-image-hotspot.php:555
Maintenance & Trust

Image Hotspot by DevVN Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 11, 2025
PHP min version
Downloads382K

Community Trust

Rating86/100
Number of ratings29
Active installs30K
Developer Profile

Image Hotspot by DevVN Developer Profile

Le Van Toan

8 plugins · 44K total installs

84
trust score
Avg Security Score
94/100
Avg Patch Time
85 days
View full developer profile
Detection Fingerprints

How We Detect Image Hotspot by DevVN

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Image Hotspot by DevVN