Image Hotspots Field for ACF Security & Risk Analysis

wordpress.org/plugins/image-hotspots-field-for-acf

Capture coordinates on images for interactive hotspots. Fork with full Gutenberg block editor support.

30 active installs v0.2 PHP 7.2+ WP 5.8+ Updated Dec 5, 2025
acfadvanced-custom-fieldscoordinateshotspotsimage-mapping
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Image Hotspots Field for ACF Safe to Use in 2026?

Generally Safe

Score 100/100

Image Hotspots Field for ACF has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "image-hotspots-field-for-acf" plugin version 0.2 exhibits a generally strong security posture based on the provided static analysis. There are no identified dangerous functions, no file operations, no external HTTP requests, and importantly, no SQL queries that do not utilize prepared statements. The absence of known vulnerabilities and CVEs in its history further supports this positive assessment, suggesting a history of secure development or diligent patching by maintainers. However, a significant concern is the complete lack of capability checks and nonce checks. While the attack surface appears minimal with zero identified entry points, the absence of these fundamental security mechanisms means that if any new entry points are introduced or discovered, they would be entirely unprotected. The mixed results in output escaping (60% properly escaped) also indicate a potential for cross-site scripting (XSS) vulnerabilities if the unescaped outputs are user-controlled.

Despite the apparent lack of direct vulnerabilities in this version, the absence of capability and nonce checks represents a foundational security weakness. This could lead to privilege escalation or unauthorized actions if an attacker can find a way to trigger code execution, even without a direct AJAX handler or REST API endpoint. The plugin's minimal attack surface is a strength, but it cannot compensate for the lack of basic access control and input validation mechanisms. In conclusion, while the plugin has avoided known vulnerabilities and employs good practices like prepared statements, the absence of critical security checks leaves it susceptible to future threats.

Key Concerns

  • Missing capability checks
  • Missing nonce checks
  • Unescaped output detected
Vulnerabilities
None known

Image Hotspots Field for ACF Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Image Hotspots Field for ACF Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

60% escaped5 total outputs
Attack Surface

Image Hotspots Field for ACF Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionacf/include_field_typesacf-image-hotspots.php:52
actionacf/register_fieldsacf-image-hotspots.php:53
actionadmin_noticesacf-image-hotspots.php:77
Maintenance & Trust

Image Hotspots Field for ACF Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 5, 2025
PHP min version7.2
Downloads715

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Image Hotspots Field for ACF Developer Profile

Levels Branding and Webdevelopment

2 plugins · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Image Hotspots Field for ACF

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/image-hotspots-field-for-acf/assets/js/input.js/wp-content/plugins/image-hotspots-field-for-acf/assets/css/input.css
Script Paths
/wp-content/plugins/image-hotspots-field-for-acf/assets/js/input.js
Version Parameters
image-hotspots-field-for-acf/assets/js/input.js?ver=image-hotspots-field-for-acf/assets/css/input.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Image Hotspots Field for ACF