
Image Hotspot by DevVN Security & Risk Analysis
wordpress.org/plugins/devvn-image-hotspotImage Hotspot by DevVN helps you add hotspots to your images.
Is Image Hotspot by DevVN Safe to Use in 2026?
Generally Safe
Score 96/100Image Hotspot by DevVN has a strong security track record. Known vulnerabilities have been patched promptly.
The devvn-image-hotspot plugin exhibits a mixed security posture. While it demonstrates good practices in several areas, including the complete use of prepared statements for SQL queries and a high percentage of properly escaped output, significant concerns remain. The presence of two instances of the dangerous `unserialize` function, especially without clear evidence of sanitization or input validation surrounding its usage, is a notable risk. Although taint analysis shows no identified flows with unsanitized paths, this could be a limitation of the analysis rather than a true absence of risk, particularly given the `unserialize` function.
The vulnerability history, with two known CVEs including one high and one medium severity vulnerability, points to past security weaknesses, specifically Cross-site Scripting and Code Injection. The fact that the last vulnerability was in 2026 suggests an effort to address past issues, but the existence of these vulnerabilities indicates a potential for similar issues to re-emerge if not carefully monitored and mitigated. The lack of currently unpatched vulnerabilities is a positive sign, but the historical pattern warrants caution.
In conclusion, while the plugin has strengths in its handling of SQL and output, the potential risks associated with `unserialize` and the historical pattern of vulnerabilities, particularly those related to input manipulation, necessitate careful review and potential patching. The limited attack surface and existing checks are positive, but the identified code signals and past CVEs suggest that vigilance is still required.
Key Concerns
- Dangerous function unserialize present
- High severity CVE in history
- Medium severity CVE in history
Image Hotspot by DevVN Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Image Hotspot by DevVN <= 1.2.9 - Authenticated (Author+) Stored Cross-Site Scripting via Custom Field Meta
Image Hotspot by DevVN <= 1.2.5 - Authenticated (Author+) PHP Object Injection
Image Hotspot by DevVN Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Image Hotspot by DevVN Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 19
Maintenance & Trust
Image Hotspot by DevVN Maintenance & Trust
Maintenance Signals
Community Trust
Image Hotspot by DevVN Alternatives
Hotspot
hotspot
Create an awesome pins for your image. It can be use for any highlighted points and dots on your image.
Interactive Image Map Plugin – Draw Attention
draw-attention
Create interactive images with clickable hotspots, using modern image maps for WordPress. Perfect for floor plans, infographics, maps, and more.
Shoppable Images (Lookbook) for WooCommerce
mabel-shoppable-images-lite
Create interactive 'shoppable' images (lookbooks) with click-to-buy tags. Ideal to showcase your products in a different way and drive more traffic.
Image Hotspot – Map Image Annotation
image-map-hotspots
Image hotspot lets you easily add custom tooltips to your images and add hotspot when highlighting them. Furthermore, you have the option of setting c …
Vision – Interactive Image Map Builder
vision
Empower your site with interactive visuals! Our plugin seamlessly transforms static images into engaging media, enabling publishers and bloggers.
Image Hotspot by DevVN Developer Profile
8 plugins · 44K total installs
How We Detect Image Hotspot by DevVN
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.