
Image Hotspots Field for ACF Security & Risk Analysis
wordpress.org/plugins/image-hotspots-field-for-acfCapture coordinates on images for interactive hotspots. Fork with full Gutenberg block editor support.
Is Image Hotspots Field for ACF Safe to Use in 2026?
Generally Safe
Score 100/100Image Hotspots Field for ACF has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "image-hotspots-field-for-acf" plugin version 0.2 exhibits a generally strong security posture based on the provided static analysis. There are no identified dangerous functions, no file operations, no external HTTP requests, and importantly, no SQL queries that do not utilize prepared statements. The absence of known vulnerabilities and CVEs in its history further supports this positive assessment, suggesting a history of secure development or diligent patching by maintainers. However, a significant concern is the complete lack of capability checks and nonce checks. While the attack surface appears minimal with zero identified entry points, the absence of these fundamental security mechanisms means that if any new entry points are introduced or discovered, they would be entirely unprotected. The mixed results in output escaping (60% properly escaped) also indicate a potential for cross-site scripting (XSS) vulnerabilities if the unescaped outputs are user-controlled.
Despite the apparent lack of direct vulnerabilities in this version, the absence of capability and nonce checks represents a foundational security weakness. This could lead to privilege escalation or unauthorized actions if an attacker can find a way to trigger code execution, even without a direct AJAX handler or REST API endpoint. The plugin's minimal attack surface is a strength, but it cannot compensate for the lack of basic access control and input validation mechanisms. In conclusion, while the plugin has avoided known vulnerabilities and employs good practices like prepared statements, the absence of critical security checks leaves it susceptible to future threats.
Key Concerns
- Missing capability checks
- Missing nonce checks
- Unescaped output detected
Image Hotspots Field for ACF Security Vulnerabilities
Image Hotspots Field for ACF Code Analysis
Output Escaping
Image Hotspots Field for ACF Attack Surface
WordPress Hooks 3
Maintenance & Trust
Image Hotspots Field for ACF Maintenance & Trust
Maintenance Signals
Community Trust
Image Hotspots Field for ACF Alternatives
ACF Content Analysis for Yoast SEO
acf-content-analysis-for-yoast-seo
WordPress plugin that adds the content of all ACF fields to the Yoast SEO score analysis.
Advanced Custom Fields: Font Awesome Field
advanced-custom-fields-font-awesome
Adds a new 'Font Awesome Icon' field to the popular Advanced Custom Fields plugin.
Table Field Add-on for ACF and SCF
advanced-custom-fields-table-field
A Table Field Add-on for the Advanced Custom Fields and Secure Custom Fields Plugin.
ACF: Better Search
acf-better-search
This plugin adds to default WordPress search engine the ability to search by content from selected fields of Advanced Custom Fields plugin.
WP All Import – Import Add-On for ACF
csv-xml-import-for-acf
Drag & drop to import any CSV, Excel, XML, or Google Sheets file into Advanced Custom Fields. Supports repeaters, flexible content, galleries, and …
Image Hotspots Field for ACF Developer Profile
2 plugins · 100 total installs
How We Detect Image Hotspots Field for ACF
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/image-hotspots-field-for-acf/assets/js/input.js/wp-content/plugins/image-hotspots-field-for-acf/assets/css/input.css/wp-content/plugins/image-hotspots-field-for-acf/assets/js/input.jsimage-hotspots-field-for-acf/assets/js/input.js?ver=image-hotspots-field-for-acf/assets/css/input.css?ver=