
Heurilens UX Analyzer Security & Risk Analysis
wordpress.org/plugins/heurilens-ux-analyzerAI-powered UX analysis for WordPress. Get actionable recommendations to improve user experience on your pages.
Is Heurilens UX Analyzer Safe to Use in 2026?
Generally Safe
Score 100/100Heurilens UX Analyzer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The heurilens-ux-analyzer plugin version 1.0.5 presents a mixed security posture. On the positive side, the plugin demonstrates good practices in areas like SQL query handling, with 100% of queries using prepared statements, and proper output escaping for all outputs. It also has a clean vulnerability history with no known CVEs, suggesting a history of secure development or prompt patching.
However, a significant concern lies within its attack surface. The plugin exposes 5 AJAX handlers, all of which lack authentication checks. This means any unauthenticated user could potentially trigger these actions, posing a considerable risk. While taint analysis did not reveal critical or high severity flows, the presence of 2 flows with unsanitized paths, even if low severity, warrants attention, especially when combined with unprotected entry points. The plugin also includes 5 nonce checks and 4 capability checks, which is a good start, but these are undermined by the fact that all AJAX handlers are missing these crucial security layers.
In conclusion, while the plugin's internal code quality regarding SQL and output is strong, the unprotected AJAX endpoints represent a serious weakness. The lack of authentication on these handlers is the most prominent security concern and a primary target for potential exploitation. The vulnerability history being clean is positive but doesn't negate the current risks posed by the code's structure.
Key Concerns
- 5 AJAX handlers without auth checks
- 2 flows with unsanitized paths
Heurilens UX Analyzer Security Vulnerabilities
Heurilens UX Analyzer Code Analysis
Output Escaping
Data Flow Analysis
Heurilens UX Analyzer Attack Surface
AJAX Handlers 5
WordPress Hooks 3
Maintenance & Trust
Heurilens UX Analyzer Maintenance & Trust
Maintenance Signals
Community Trust
Heurilens UX Analyzer Alternatives
Button It Up
button-it-up
Button It Up changes the upload/insert button style to look like an actual button.
WCAG 2.0 form fields for Gravity Forms
gravity-forms-wcag-20-form-fields
Modifies Gravity Forms form fields and improves validation so that forms meet WCAG 2.0 accessibility requirements.
Tada: Instant Webpage Loading, Fast Website Browsing
tada
Make your website load more quickly.
Focusable – Focus Ring On Any Element
focusable
Make your website instantly more accessible! Focusable restores and enhances the visible focus ring for keyboard users, ensuring everyone can navigate …
SiteEase Accessibility Pro
site-accessibility
SiteEase Accessibility Pro improves website readability and usability by allowing users to adjust font size, colors, and other visual settings.
Heurilens UX Analyzer Developer Profile
1 plugin · 0 total installs
How We Detect Heurilens UX Analyzer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/heurilens-ux-analyzer/admin/css/admin.css/wp-content/plugins/heurilens-ux-analyzer/admin/js/admin.js/wp-content/plugins/heurilens-ux-analyzer/admin/js/admin.jsheurilens-ux-analyzer/admin/css/admin.css?ver=heurilens-ux-analyzer/admin/js/admin.js?ver=HTML / DOM Fingerprints
data-heurilens-analyzer-targetheurilens/wp-json/heurilens/v1/analyze