
CM Tooltip Glossary Security & Risk Analysis
wordpress.org/plugins/enhanced-tooltipglossaryTransform jargon into engaging content that boosts SEO, drives engagement, improves conversions, with automatic links and tooltips.
Is CM Tooltip Glossary Safe to Use in 2026?
Generally Safe
Score 97/100CM Tooltip Glossary has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "enhanced-tooltipglossary" plugin version 4.5.3 presents a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and implementing nonce checks and capability checks for most entry points. The absence of any currently unpatched CVEs is also a significant strength, indicating the developers are responsive to security issues. However, the static analysis reveals several areas of concern. A notable weakness is the presence of 3 unprotected AJAX handlers, representing a significant attack surface that could be exploited by unauthenticated users. While taint analysis shows no critical or high severity flows, one flow with an unsanitized path indicates a potential for unexpected behavior or vulnerabilities if not carefully handled. The high number of total outputs with only 31% properly escaped suggests a risk of Cross-Site Scripting (XSS) vulnerabilities, especially in conjunction with past vulnerabilities of this type. The plugin's history of 7 medium severity CVEs, primarily related to XSS and CSRF, further reinforces the concern about input sanitization and output escaping, suggesting these have been recurring issues. The plugin also makes external HTTP requests, which, without proper validation, could lead to SSRF or other vulnerabilities. The bundled Select2 library, while common, should also be kept updated to avoid known vulnerabilities within it. Overall, while the plugin has improved in certain areas like SQL practices and has no active critical issues, the presence of unprotected AJAX handlers, poor output escaping, and a history of XSS/CSRF vulnerabilities warrant caution.
Key Concerns
- Unprotected AJAX handlers
- Low output escaping percentage
- Flows with unsanitized paths
- Multiple past medium CVEs (XSS/CSRF)
- External HTTP requests
CM Tooltip Glossary Security Vulnerabilities
CVEs by Year
Severity Breakdown
7 total CVEs
CM Tooltip Glossary <= 4.3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
CM Tooltip Glossary <= 4.3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
CM Tooltip Glossary <= 4.3.3 - Authenticated (Admin+) Stored Cross-Site Scripting
CM Tooltip Glossary – Powerful Glossary Plugin <= 4.2.11 - Cross-Site Request Forgery
CM Tooltip Glossary <= 3.9.20 - Authenticated Stored Cross-Site Scripting
CM Tooltip Glossary – Better SEO and UEX for your WP site <= 3.3.4 - Reflected Cross-Site Scripting
CM Tooltip Glossary – Better SEO and UEX for your WP site <= 3.1.3 - Reflected Cross-Site Scripting
CM Tooltip Glossary Release Timeline
CM Tooltip Glossary Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
CM Tooltip Glossary Attack Surface
AJAX Handlers 5
Shortcodes 9
WordPress Hooks 172
Maintenance & Trust
CM Tooltip Glossary Maintenance & Trust
Maintenance Signals
Community Trust
CM Tooltip Glossary Alternatives
Glossary
glossary-by-codeat
Boost your SEO & UX with Codeat's Glossary: powerful auto-link engine; customizable tooltips, mobile settings, ChatGPT and much more!
Glossary Tooltip – Build a Smart Knowledge Base with Tooltips
glossary-tooltip
Create a powerful glossary knowledge base to boost SEO, increase engagement, improve conversions with automatic links and tooltips.
Encyclopedia / Glossary / Wiki
encyclopedia-lexicon-glossary-wiki-dictionary
Supercharged tool to build your own awesome Encyclopedia / Lexicon / Glossary / Wiki / Dictionary / Knowledge base / Directory / Vocabulary in no time
iThoughts Tooltip Glossary
ithoughts-tooltip-glossary
Create beautiful tooltips for descriptions or glossary terms, easily
Glossary Pages
glossary-pages
A customizable, multilingual-ready glossary plugin with A-Z navigation, category filters, and search. Lightweight, flexible, and SEO-friendly.
CM Tooltip Glossary Developer Profile
19 plugins · 22K total installs
How We Detect CM Tooltip Glossary
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/enhanced-tooltipglossary/assets/css/cmtt-tooltip.css/wp-content/plugins/enhanced-tooltipglossary/assets/css/cmtt.css/wp-content/plugins/enhanced-tooltipglossary/assets/js/jquery.cookie.js/wp-content/plugins/enhanced-tooltipglossary/assets/js/cmtt.js/wp-content/plugins/enhanced-tooltipglossary/assets/js/cmtt-admin.js/wp-content/plugins/enhanced-tooltipglossary/assets/js/jquery.sticky-kit.min.js/wp-content/plugins/enhanced-tooltipglossary/assets/js/cmtt-frontend.js/wp-content/plugins/enhanced-tooltipglossary/assets/js/jquery.cookie.js/wp-content/plugins/enhanced-tooltipglossary/assets/js/cmtt.js/wp-content/plugins/enhanced-tooltipglossary/assets/js/cmtt-admin.js/wp-content/plugins/enhanced-tooltipglossary/assets/js/jquery.sticky-kit.min.js/wp-content/plugins/enhanced-tooltipglossary/assets/js/cmtt-frontend.jsenhanced-tooltipglossary/assets/css/cmtt-tooltip.css?ver=enhanced-tooltipglossary/assets/css/cmtt.css?ver=enhanced-tooltipglossary/assets/js/jquery.cookie.js?ver=enhanced-tooltipglossary/assets/js/cmtt.js?ver=enhanced-tooltipglossary/assets/js/cmtt-admin.js?ver=enhanced-tooltipglossary/assets/js/jquery.sticky-kit.min.js?ver=enhanced-tooltipglossary/assets/js/cmtt-frontend.js?ver=HTML / DOM Fingerprints
cmtt-tooltipcmtt-tooltip-contentcmtt-tooltip-arrowcmtt-glossary-index<!-- BEGIN CMTOOLTIPGLOSSARY --><!-- END CMTOOLTIPGLOSSARY -->data-cmtt-iddata-cmtt-contentCMTT_settingscmtt_lang[glossary_frontend_form][glossary_index]