
iThoughts Tooltip Glossary Security & Risk Analysis
wordpress.org/plugins/ithoughts-tooltip-glossaryCreate beautiful tooltips for descriptions or glossary terms, easily
Is iThoughts Tooltip Glossary Safe to Use in 2026?
Generally Safe
Score 85/100iThoughts Tooltip Glossary has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ithoughts-tooltip-glossary" plugin v3.0.3 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and has no recorded vulnerability history, indicating a relatively secure development past. The absence of critical or high severity taint flows and dangerous functions is also reassuring.
However, several areas raise concerns. The plugin presents a significant attack surface with 14 AJAX handlers, a notable 7 of which lack authentication checks. While there are 7 nonce checks and 5 capability checks present, the high number of unprotected AJAX endpoints represents a potential avenue for unauthorized actions. Furthermore, the static analysis reveals that only 53% of output is properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled securely before being displayed.
While the plugin has a clean vulnerability history, the current static analysis findings, particularly the unprotected AJAX handlers and insufficient output escaping, warrant attention. These factors, combined with the relatively large number of entry points, suggest that while major vulnerabilities are not immediately apparent from historical data or taint analysis, there are structural weaknesses that could be exploited. A cautious approach is recommended, prioritizing the securing of AJAX endpoints and improving output sanitization.
Key Concerns
- Unprotected AJAX handlers
- Low percentage of properly escaped output
- Large attack surface without clear auth
iThoughts Tooltip Glossary Security Vulnerabilities
iThoughts Tooltip Glossary Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
iThoughts Tooltip Glossary Attack Surface
AJAX Handlers 14
Shortcodes 8
WordPress Hooks 50
Maintenance & Trust
iThoughts Tooltip Glossary Maintenance & Trust
Maintenance Signals
Community Trust
iThoughts Tooltip Glossary Alternatives
CM Tooltip Glossary
enhanced-tooltipglossary
Transform jargon into engaging content that boosts SEO, drives engagement, improves conversions, with automatic links and tooltips.
Glossary
glossary-by-codeat
Boost your SEO & UX with Codeat's Glossary: powerful auto-link engine; customizable tooltips, mobile settings, ChatGPT and much more!
Glossary Tooltip – Build a Smart Knowledge Base with Tooltips
glossary-tooltip
Create a powerful glossary knowledge base to boost SEO, increase engagement, improve conversions with automatic links and tooltips.
Easy Glossary
easy-glossary
A lightweight, flexible glossary plugin that auto-links terms, shows tooltips, and provides an index shortcode.
Tooltips for WordPress
wordpress-tooltips
Add custom tooltip automatically for post's content/title/tag/excerpt/gallery/menu, easily add image / video / audio / social/link tooltips
iThoughts Tooltip Glossary Developer Profile
3 plugins · 40 total installs
How We Detect iThoughts Tooltip Glossary
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ithoughts-tooltip-glossary/js/dist/ithoughts_tt_gl-admin.js/wp-content/plugins/ithoughts-tooltip-glossary/js/dist/ithoughts_tt_gl-tinymce-forms.js/wp-content/plugins/ithoughts-tooltip-glossary/js/dist/ithoughts_tt_gl-updater.js/wp-content/plugins/ithoughts-tooltip-glossary/js/dist/ithoughts_tt_gl-floater.js/wp-content/plugins/ithoughts-tooltip-glossary/js/dist/ithoughts_tt_gl-styleeditor.js/wp-content/plugins/ithoughts-tooltip-glossary/js/dist/ithoughts_tt_gl-editor.js/wp-content/plugins/ithoughts-tooltip-glossary/css/ithoughts_tt_gl-tinymce-forms.min.css/wp-content/plugins/ithoughts-tooltip-glossary/css/ithoughts_tt_gl-admin.min.cssHTML / DOM Fingerprints
ithoughts_tt_gl-editor-containerithoughts_tt_gl-tooltip-previewithoughts_tt_gl-style-editor-wrapper<!-- ithoughts-tooltip-glossary -->data-iThoughtsTooltipGlossarydata-ithoughts-tt-gl-admin-ajaxdata-ithoughts-tt-gl-base-tinymcedata-ithoughts-tt-gl-verbositydata-ithoughts-tt-gl-nonceiThoughtsTooltipGlossaryEditor