Reactflow Visitor Recording and Heatmaps Security & Risk Analysis

wordpress.org/plugins/reactflow-session-replay-heatmap

Convert your prospects into customers. Reactflow highlights visual and logical reason why your visitors are not turning into customers, Optimize conve …

300 active installs v1.0.11 PHP 5.0+ WP 2.7+ Updated May 9, 2025
analyticsconversionfunnelheatmapsrecording
79
B · Generally Safe
CVEs total1
Unpatched1
Last CVEDec 20, 2024
Safety Verdict

Is Reactflow Visitor Recording and Heatmaps Safe to Use in 2026?

Mostly Safe

Score 79/100

Reactflow Visitor Recording and Heatmaps is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Dec 20, 2024Updated 10mo ago
Risk Assessment

The plugin 'reactflow-session-replay-heatmap' v1.0.11 demonstrates several good security practices, including the complete absence of direct SQL queries and a single external HTTP request that might be legitimate. Furthermore, the static analysis shows a low attack surface with no unprotected AJAX handlers, REST API routes, shortcodes, or cron events, and only one instance of a nonce and capability check, suggesting a controlled and authenticated entry point. However, the low percentage of properly escaped output (34%) presents a significant concern, indicating a high likelihood of cross-site scripting (XSS) vulnerabilities. This is corroborated by its vulnerability history, which includes a medium-severity CVE for XSS and a recent unpatched vulnerability of the same type. The presence of even one unpatched vulnerability, especially of medium severity and XSS, warrants immediate attention. While the plugin appears to have a solid foundation regarding input handling and access control, the lack of comprehensive output escaping is a critical weakness that could be exploited.

Key Concerns

  • Unpatched medium severity CVE (XSS)
  • Low output escaping percentage (34%)
  • 1 external HTTP request
Vulnerabilities
1

Reactflow Visitor Recording and Heatmaps Security Vulnerabilities

CVEs by Year

1 CVE in 2024 · unpatched
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-11975medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Reactflow Visitor Recording and Heatmaps <= 1.0.10 - Reflected Cross-Site Scripting

Dec 20, 2024Unpatched
Code Analysis
Analyzed Mar 16, 2026

Reactflow Visitor Recording and Heatmaps Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
66
34 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

34% escaped100 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
rcf_optionpage (reactflow.php:236)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Reactflow Visitor Recording and Heatmaps Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_menureactflow.php:10
actionwp_footerreactflow.php:11
actionwp_headreactflow.php:12
actionplugins_loadedreactflow.php:23
actionadmin_noticesreactflow.php:184
actionwp_dashboard_setupreactflow.php:949
filterplugin_action_linksreactflow.php:953
Maintenance & Trust

Reactflow Visitor Recording and Heatmaps Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 9, 2025
PHP min version5.0
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs300
Developer Profile

Reactflow Visitor Recording and Heatmaps Developer Profile

reactflow

1 plugin · 300 total installs

79
trust score
Avg Security Score
79/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Reactflow Visitor Recording and Heatmaps

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/reactflow-session-replay-heatmap/reactflow.js
Script Paths
/wp-content/plugins/reactflow-session-replay-heatmap/reactflow.js
Version Parameters
reactflow-session-replay-heatmap/reactflow.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Reactflow WP v1.0.11 -->
JS Globals
reactflow_tracker
FAQ

Frequently Asked Questions about Reactflow Visitor Recording and Heatmaps