Interactive Image Map Builder Security & Risk Analysis

wordpress.org/plugins/interactive-image-map-builder

Clickable hotspots can be easily created with this plugin. A great way to display image maps, floor plans, and more.

1K active installs v3.0 PHP 5.6+ WP 5.4+ Updated Aug 15, 2025
draw-floor-planimage-canvasimage-labeling-toolinteractive-image-mapinteractive-image-map-builder
100
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 14, 2023
Safety Verdict

Is Interactive Image Map Builder Safe to Use in 2026?

Generally Safe

Score 100/100

Interactive Image Map Builder has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Feb 14, 2023Updated 7mo ago
Risk Assessment

The security posture of the interactive-image-map-builder plugin v3.0 appears to be generally good, with a strong emphasis on secure coding practices. The plugin exhibits a low attack surface with no unprotected entry points and a high percentage of properly escaped output and prepared SQL statements. Nonce and capability checks are also present, which are crucial for preventing common web vulnerabilities. The lack of critical or high severity taint flows is a positive sign, indicating that the plugin is not immediately susceptible to severe code execution or sensitive data leakage issues.

However, there are areas for concern. The presence of unsanitized paths in taint analysis, even at lower severities, suggests a potential for path traversal vulnerabilities, which could allow attackers to access sensitive files or directories. While the plugin has had a past medium severity CVE related to Cross-Site Scripting, it is currently unpatched. This indicates that while the developers are aware of security and have addressed issues, ongoing vigilance and prompt patching of any future vulnerabilities are essential. The plugin's overall security is bolstered by its limited attack surface and good coding practices, but the presence of unsanitized paths and the history of a past vulnerability warrant continued monitoring.

Key Concerns

  • Flows with unsanitized paths detected
  • Medium severity CVE exists, not specified as patched
  • SQL queries not using prepared statements: 64%
  • Output not properly escaped: 14%
Vulnerabilities
1

Interactive Image Map Builder Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-25704medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Interactive SVG Image Map Builder <= 1.0 - Authenticated(Admin+) Stored Cross-Site Scripting

Feb 14, 2023 Patched in 1.1 (343d)
Code Analysis
Analyzed Mar 16, 2026

Interactive Image Map Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
34
19 prepared
Unescaped Output
30
188 escaped
Nonce Checks
5
Capability Checks
2
File Operations
3
External Requests
1
Bundled Libraries
0

SQL Query Safety

36% prepared53 total queries

Output Escaping

86% escaped218 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

5 flows2 with unsanitized paths
<home> (home.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Interactive Image Map Builder Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[isimb_6310_builder] index.php:22
WordPress Hooks 7
actionadmin_menuindex.php:34
actionwp_enqueue_scriptsindex.php:55
actionwp_enqueue_scriptsindex.php:65
actionactivated_pluginindex.php:73
actionadmin_enqueue_scriptsindex.php:75
actionplugins_loadedindex.php:81
actionwp_enqueue_scriptsindex.php:90
Maintenance & Trust

Interactive Image Map Builder Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 15, 2025
PHP min version5.6
Downloads17K

Community Trust

Rating100/100
Number of ratings17
Active installs1K
Alternatives

Interactive Image Map Builder Alternatives

No alternatives data available yet.

Developer Profile

Interactive Image Map Builder Developer Profile

mehjabin6310

1 plugin · 1K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
343 days
View full developer profile
Detection Fingerprints

How We Detect Interactive Image Map Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/interactive-image-map-builder/assets/css/style.css/wp-content/plugins/interactive-image-map-builder/assets/css/jquery.minicolors.css/wp-content/plugins/interactive-image-map-builder/assets/css/fontselect.css/wp-content/plugins/interactive-image-map-builder/assets/js/fontselect.js/wp-content/plugins/interactive-image-map-builder/assets/js/isimb-6310-common.js/wp-content/plugins/interactive-image-map-builder/assets/js/json-data.js/wp-content/plugins/interactive-image-map-builder/assets/js/isimb-6310-admin-script.js/wp-content/plugins/interactive-image-map-builder/assets/js/isimb-6310-admin-modal.js+2 more
Script Paths
https://cdnjs.cloudflare.com/ajax/libs/codemirror/5.48.0/codemirror.min.jshttps://cdnjs.cloudflare.com/ajax/libs/jquery-minicolors/2.3.4/jquery.minicolors.min.jshttps://cdnjs.cloudflare.com/ajax/libs/jqueryui/1.12.1/jquery-ui.min.js

HTML / DOM Fingerprints

CSS Classes
isimb-6310-main-svgisimb-6310-hover-contentisimb-6310-modal-contentisimb-6310-searchisimb-6310-search-containerisimb-6310-search-template-isimb-6310-builder
JS Globals
isimb_6310_ajax_objectmy_ajax_object
Shortcode Output
[isimb_6310_builder id="
FAQ

Frequently Asked Questions about Interactive Image Map Builder