ProHotspots Lite – Image Gallery Hotspots Security & Risk Analysis

wordpress.org/plugins/prohotpoints-gallery

Create custom hotspots to make your images more informative and interactive using the WordPress blocks.

40 active installs v1.0.0 PHP 7.0+ WP 5.1+ Updated Feb 20, 2019
amazon-hotspotcustom-hotspotshotpointhotspotwoocommerce-hotspot
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is ProHotspots Lite – Image Gallery Hotspots Safe to Use in 2026?

Generally Safe

Score 85/100

ProHotspots Lite – Image Gallery Hotspots has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The 'prohotpoints-gallery' v1.0.0 plugin exhibits a concerning security posture due to significant unprotected entry points. While the static analysis reveals no dangerous functions, SQL injection risks (100% prepared statements), and all outputs are properly escaped, the absence of authorization checks on its two AJAX handlers is a critical oversight. This lack of protection means that any unauthenticated user could potentially trigger these AJAX actions, leading to unintended consequences depending on their functionality. The plugin also shows no history of vulnerabilities, which might suggest good development practices or simply that it hasn't been targeted or extensively analyzed. However, the presence of unprotected AJAX endpoints represents a clear and immediate risk that needs to be addressed.

Key Concerns

  • Unprotected AJAX handlers
  • Missing Nonce checks on AJAX handlers
Vulnerabilities
None known

ProHotspots Lite – Image Gallery Hotspots Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ProHotspots Lite – Image Gallery Hotspots Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface
2 unprotected

ProHotspots Lite – Image Gallery Hotspots Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_AAT_HPCL_ajax_requestblocks\index.php:27
noprivwp_ajax_AAT_HPCL_ajax_requestblocks\index.php:28
WordPress Hooks 2
actioninitblocks\index.php:25
filteraffIDindex.php:52
Maintenance & Trust

ProHotspots Lite – Image Gallery Hotspots Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedFeb 20, 2019
PHP min version7.0
Downloads3K

Community Trust

Rating60/100
Number of ratings3
Active installs40
Developer Profile

ProHotspots Lite – Image Gallery Hotspots Developer Profile

AA-Team

3 plugins · 70 total installs

78
trust score
Avg Security Score
77/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ProHotspots Lite – Image Gallery Hotspots

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/prohotpoints-gallery/frontend/frontend.view.css/wp-content/plugins/prohotpoints-gallery/frontend/frontend.build.js/wp-content/plugins/prohotpoints-gallery/backend/backend.build.js/wp-content/plugins/prohotpoints-gallery/backend/backend.editor.css
Script Paths
frontend/frontend.view.cssfrontend/frontend.build.jsbackend/backend.build.jsbackend/backend.editor.css

HTML / DOM Fingerprints

CSS Classes
wp-block-aaphotspots-hotspots
Data Attributes
data-wp-blocks
JS Globals
AAT_HPCL
FAQ

Frequently Asked Questions about ProHotspots Lite – Image Gallery Hotspots