PicPoints Security & Risk Analysis

wordpress.org/plugins/picpoints

Create interactive images with clickable hotspots for WordPress.

0 active installs v1.0.0 PHP 7.0+ WP 4.6+ Updated Apr 22, 2025
hotspotsimage-mapinteractive-images
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PicPoints Safe to Use in 2026?

Generally Safe

Score 100/100

PicPoints has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The picpoints plugin v1.0.0 exhibits a strong security posture based on the provided static analysis. There are no identified entry points in the attack surface, meaning no AJAX handlers, REST API routes, shortcodes, or cron events are exposed. This significantly reduces the potential for external code execution or manipulation. Furthermore, the code demonstrates excellent security practices with 100% of SQL queries using prepared statements and 100% of outputs being properly escaped. The absence of dangerous functions, file operations, external HTTP requests, and the lack of taint analysis findings all point to a well-written and secure codebase.

Vulnerabilities
None known

PicPoints Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

PicPoints Release Timeline

v1.0.0Current
Code Analysis
Analyzed Mar 17, 2026

PicPoints Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped8 total outputs
Attack Surface

PicPoints Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filterno_texturize_shortcodesincludes\Frontend.php:6
actionplugins_loadedincludes\Plugin.php:10
actionafter_setup_themeincludes\Plugin.php:11
Maintenance & Trust

PicPoints Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 22, 2025
PHP min version7.0
Downloads684

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

PicPoints Developer Profile

Yalogica

11 plugins · 120 total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect PicPoints

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/picpoints/assets/css/main.css
Version Parameters
picpoints/assets/css/main.css?ver=1.0.0

HTML / DOM Fingerprints

CSS Classes
pnts-containerpnts-hotspotspnts-hotspot
Data Attributes
data-xdata-ydata-link
Shortcode Output
<div class='pnts-container<img src='<div class='pnts-hotspots'><a class='pnts-hotspot'
FAQ

Frequently Asked Questions about PicPoints