
Interactive Image Map Plugin – Draw Attention Security & Risk Analysis
wordpress.org/plugins/draw-attentionCreate interactive images with clickable hotspots, using modern image maps for WordPress. Perfect for floor plans, infographics, maps, and more.
Is Interactive Image Map Plugin – Draw Attention Safe to Use in 2026?
Generally Safe
Score 99/100Interactive Image Map Plugin – Draw Attention has a strong security track record. Known vulnerabilities have been patched promptly.
The 'draw-attention' plugin version 2.1.2 exhibits a generally positive security posture with no critical or high severity vulnerabilities identified in the static analysis or vulnerability history. The plugin demonstrates good security practices by implementing nonce and capability checks, and it has no unpatched CVEs. The absence of dangerous functions, file operations, and external HTTP requests is also encouraging.
However, there are areas for improvement. The relatively low percentage of properly escaped output (13%) suggests a potential risk of Cross-Site Scripting (XSS) vulnerabilities, even though no specific flows were identified in the taint analysis. Similarly, the 50% usage of prepared statements for SQL queries indicates that half of the SQL queries are executed without this crucial security measure, which could be exploited for SQL injection if not handled carefully elsewhere. The presence of two medium severity vulnerabilities in its history, specifically related to improper access control and missing authorization, warrants attention and suggests that while currently patched, these types of issues have occurred in the past.
Overall, 'draw-attention' v2.1.2 is reasonably secure due to the lack of critical immediate threats and a proactive approach to patching historical vulnerabilities. However, the plugin would benefit from a comprehensive review of its output escaping and a more consistent application of prepared statements to mitigate potential XSS and SQL injection risks.
Key Concerns
- Low output escaping percentage (13%)
- 50% of SQL queries not using prepared statements
- 2 past medium vulnerabilities (Improper Access Control, Missing Authorization)
Interactive Image Map Plugin – Draw Attention Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Draw Attention <= 2.0.15 - Improper Access Control via register_cpt
Draw Attention <= 2.0.11 - Missing Authorization to Arbitrary Post Featured Image Modification
Interactive Image Map Plugin – Draw Attention Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Interactive Image Map Plugin – Draw Attention Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 52
Maintenance & Trust
Interactive Image Map Plugin – Draw Attention Maintenance & Trust
Maintenance Signals
Community Trust
Interactive Image Map Plugin – Draw Attention Alternatives
Vision – Interactive Image Map Builder
vision
Empower your site with interactive visuals! Our plugin seamlessly transforms static images into engaging media, enabling publishers and bloggers.
Interactive Image – Real Estate Visualizer & Image Map
interactive-real-estate
⚡ Create interactive images with clickable zones on svg. Display floor plans, image maps, property details and 2D/3D photos. No coding required.
Image Map Connect – Display Posts as Image Hotspots
image-map-connect
Add any image to your WordPress posts, pages, or archives and make it interactive: display your existing and new posts as markers.
MarkerKit
markerkit
A lightweight plugin to embed interactive images and maps from MarkerKit using a shortcode or Gutenberg block.
PicPoints
picpoints
Create interactive images with clickable hotspots for WordPress.
Interactive Image Map Plugin – Draw Attention Developer Profile
4 plugins · 85K total installs
How We Detect Interactive Image Map Plugin – Draw Attention
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/draw-attention/public/js/draw-attention-public.js/wp-content/plugins/draw-attention/public/css/draw-attention-public.css/wp-content/plugins/draw-attention/public/js/draw-attention-public.jsdraw-attention/public/css/draw-attention-public.css?ver=draw-attention/public/js/draw-attention-public.js?ver=HTML / DOM Fingerprints
da-hotspotda-hotspot-wrapperda-image-mapda-image-map-container<!-- draw-attention --><!-- End draw-attention --><!-- END MAIN CONTENT --><!-- DO NOT MODIFY THIS FILE -->data-draw-attention-iddata-draw-attention-image-iddata-draw-attention-hotspot-iddata-draw-attention-zoom-effectdata-draw-attention-hotspot-click-actionDrawAttentionPublicDrawAttentionAdmin/wp-json/draw-attention/v1/hotspots[draw-attention[da_image_map