Hotspot addon for elementor Security & Risk Analysis

wordpress.org/plugins/hotspot-addon-for-elementor

It is a simple Hotspot addon for addon for elementor.After installing this plugin you will get a HOt spot widget in the elementor widget area.

40 active installs v1.0.1 PHP 5.6+ WP 4.8+ Updated Apr 23, 2025
elementorelementor-addonelementor-widgethothot-spot
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Hotspot addon for elementor Safe to Use in 2026?

Generally Safe

Score 100/100

Hotspot addon for elementor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "hotspot-addon-for-elementor" v1.0.1 plugin exhibits a strong security posture in several key areas. The absence of identified vulnerabilities in its history and the clean static analysis results, particularly the lack of dangerous functions, external HTTP requests, and file operations, are positive indicators. The plugin also demonstrates good practices by utilizing prepared statements for all SQL queries.

However, several concerns warrant attention. The complete lack of nonce checks and capability checks across all entry points (AJAX, REST API, shortcodes, cron events) is a significant weakness. While the static analysis reported zero entry points, this is an anomaly in itself and suggests a potential oversight in the analysis or the plugin's structure. A more critical concern is the significant percentage of improperly escaped output (29%). This could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed to users.

In conclusion, while the plugin avoids common pitfalls like unpatched CVEs and raw SQL, the lack of authentication/authorization checks and the considerable amount of unescaped output present substantial security risks. The absence of any identified entry points in the static analysis is unusual and requires further investigation to confirm its accuracy. The plugin's security can be significantly improved by implementing robust nonce and capability checks and addressing the unescaped output issues.

Key Concerns

  • Missing nonce checks across all entry points
  • Missing capability checks across all entry points
  • Significant unescaped output (29%)
Vulnerabilities
None known

Hotspot addon for elementor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Hotspot addon for elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
15 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

71% escaped21 total outputs
Attack Surface

Hotspot addon for elementor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actioninitwtt-hotspot-elementor-extension.php:96
actionplugins_loadedwtt-hotspot-elementor-extension.php:97
actionadmin_noticeswtt-hotspot-elementor-extension.php:135
actionadmin_noticeswtt-hotspot-elementor-extension.php:141
actionadmin_noticeswtt-hotspot-elementor-extension.php:147
actionelementor/frontend/after_enqueue_styleswtt-hotspot-elementor-extension.php:152
actionelementor/frontend/after_enqueue_scriptswtt-hotspot-elementor-extension.php:153
actionelementor/widgets/widgets_registeredwtt-hotspot-elementor-extension.php:158
actionelementor/controls/controls_registeredwtt-hotspot-elementor-extension.php:159
actionelementor/initwtt-hotspot-elementor-extension.php:162
Maintenance & Trust

Hotspot addon for elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 23, 2025
PHP min version5.6
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Hotspot addon for elementor Developer Profile

Ibrahim

6 plugins · 1K total installs

71
trust score
Avg Security Score
89/100
Avg Patch Time
112 days
View full developer profile
Detection Fingerprints

How We Detect Hotspot addon for elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hotspot-addon-for-elementor/assets/css/font-awesome.css/wp-content/plugins/hotspot-addon-for-elementor/assets/css/font-awesome.min.css/wp-content/plugins/hotspot-addon-for-elementor/assets/css/style.css/wp-content/plugins/hotspot-addon-for-elementor/assets/js/frontend.js
Script Paths
/wp-content/plugins/hotspot-addon-for-elementor/assets/js/frontend.js

HTML / DOM Fingerprints

CSS Classes
wtt-pricing-table
FAQ

Frequently Asked Questions about Hotspot addon for elementor