Image Hotspot – Map Image Annotation Security & Risk Analysis

wordpress.org/plugins/image-map-hotspots

Image hotspot lets you easily add custom tooltips to your images and add hotspot when highlighting them. Furthermore, you have the option of setting c …

3K active installs v3.5 PHP 5.6+ WP 5.4+ Updated Feb 16, 2026
hotspot-imagehotspot-image-wordpresshotspot-pictureimage-hotspotimage-hotspots
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Image Hotspot – Map Image Annotation Safe to Use in 2026?

Generally Safe

Score 100/100

Image Hotspot – Map Image Annotation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "image-map-hotspots" plugin v3.5 presents a generally good security posture, with a low attack surface and a high percentage of properly escaped outputs. The absence of known vulnerabilities and critical taint flows is a significant positive indicator. The plugin also demonstrates good practices with a majority of SQL queries utilizing prepared statements and the presence of nonce and capability checks.

Key Concerns

  • Flows with unsanitized paths
  • SQL queries without prepared statements (39% of 41)
  • Outputs not properly escaped (18% of 118)
  • File operations present
  • External HTTP requests present
Vulnerabilities
None known

Image Hotspot – Map Image Annotation Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Image Hotspot – Map Image Annotation Code Analysis

Dangerous Functions
0
Raw SQL Queries
16
25 prepared
Unescaped Output
21
97 escaped
Nonce Checks
5
Capability Checks
2
File Operations
4
External Requests
4
Bundled Libraries
0

SQL Query Safety

61% prepared41 total queries

Output Escaping

82% escaped118 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

4 flows1 with unsanitized paths
<home> (home.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Image Hotspot – Map Image Annotation Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[imh_6310_image_map] index.php:18
WordPress Hooks 5
actionadmin_menuindex.php:31
actionactivated_pluginindex.php:56
actionadmin_enqueue_scriptsindex.php:58
actionplugins_loadedindex.php:66
actionwp_enqueue_scriptsindex.php:75
Maintenance & Trust

Image Hotspot – Map Image Annotation Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 16, 2026
PHP min version5.6
Downloads54K

Community Trust

Rating98/100
Number of ratings22
Active installs3K
Developer Profile

Image Hotspot – Map Image Annotation Developer Profile

wpmart

6 plugins · 13K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
191 days
View full developer profile
Detection Fingerprints

How We Detect Image Hotspot – Map Image Annotation

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/image-map-hotspots/assets/css/google-font.css/wp-content/plugins/image-map-hotspots/assets/css/style.css/wp-content/plugins/image-map-hotspots/assets/css/jquery.minicolors.css/wp-content/plugins/image-map-hotspots/assets/css/fontselect.css/wp-content/plugins/image-map-hotspots/assets/css/codemirror.min.css/wp-content/plugins/image-map-hotspots/assets/css/jquery-ui.min.css/wp-content/plugins/image-map-hotspots/assets/js/fontselect.js/wp-content/plugins/image-map-hotspots/assets/js/jquery-ui.min.js+6 more
Script Paths
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.5.2/css/all.min.csshttps://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.5.2/css/v4-shims.min.css

HTML / DOM Fingerprints

CSS Classes
imh-6310-searchimh-6310-search-containerimh-6310-search-boxsearch-iconimh-6310-point-icons
Data Attributes
data-imh-6310-template-id
Shortcode Output
[imh_6310_image_map
FAQ

Frequently Asked Questions about Image Hotspot – Map Image Annotation