
Tooltip Crazy Security & Risk Analysis
wordpress.org/plugins/tooltip-crazyTooltip Crazy adds a new button to the TinyMCE for adding tooltips to your posts and sites via shortcode.
Is Tooltip Crazy Safe to Use in 2026?
Generally Safe
Score 85/100Tooltip Crazy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tooltip-crazy" v1.1.2 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL queries without prepared statements, and proper output escaping are all positive indicators. Furthermore, the lack of known vulnerabilities in its history suggests a well-maintained codebase or a lack of previously discovered weaknesses. The plugin's limited attack surface, with only one shortcode and no AJAX handlers or REST API routes without authentication, further bolsters its security. The presence of TinyMCE as a bundled library is a common practice and typically not a significant security concern on its own, assuming it's not an outdated or vulnerable version. However, a notable concern is the complete absence of nonce checks and capability checks for the identified entry points. While the attack surface is currently small, the lack of these fundamental WordPress security mechanisms means that if any new entry points are introduced or if existing ones are ever modified, they could be immediately vulnerable to CSRF attacks or privilege escalation if not properly secured. This oversight represents a potential weakness that could be exploited in the future.
Key Concerns
- Missing nonce checks
- Missing capability checks
Tooltip Crazy Security Vulnerabilities
Tooltip Crazy Release Timeline
Tooltip Crazy Code Analysis
Bundled Libraries
Tooltip Crazy Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Tooltip Crazy Maintenance & Trust
Maintenance Signals
Community Trust
Tooltip Crazy Alternatives
Gravity Booster – Styles & Layouts for Gravity Forms
styles-and-layouts-for-gravity-forms
Gravity Booster - Styles and Layouts for Gravity Forms plugin lets you design and style Gravity Forms without CSS coding. You can also use it for addi …
Easy Footnotes
easy-footnotes
Easy Footnotes lets you quickly and easily add footnotes throughout your WordPress posts using a simple shortcode in the text editor.
Hide Tooltips on Hover – Clean Up Title Attributes Without Losing Accessibility
hide-titles-on-hover
Hide browser tooltips on hover while preserving accessibility for screen readers.
Text Hover
text-hover
Add hover text (aka tooltips) to content in posts. Handy for providing explanations of names, terms, phrases, abbreviations, and acronyms.
Magic Tooltips For Contact Form 7
magic-tooltips-for-contact-form-7
Magic Tooltips For Contact Form 7 is a WordPress Contact Form 7 tooltip plugin that let's you add tooltips to the Contact Form 7 form fields.
Tooltip Crazy Developer Profile
2 plugins · 1K total installs
How We Detect Tooltip Crazy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
tooltip-crazy/tooltips/css/normalize.csstooltip-crazy/tooltips/css/tooltip-classic.csstooltip-crazy/tooltips/css/tooltip-bloated.csstooltip-crazy/tooltips/css/tooltip-box.csstooltip-crazy/tooltips/css/tooltip-sharp.csstooltip-crazy/tooltips/css/tooltip-line.csstooltip-crazy/style.csstooltip-crazy/js/tinymce.jsHTML / DOM Fingerprints
tooltip-classictooltip-classic-itemtooltip-classic-contenttooltip-classic-texttooltip-bloatedtooltip-bloated-contenttooltip-boxtooltip-box-item+10 moredata-tooltip-crazy-layoutdata-tooltip-crazy-effecttooltipcrazy<span class="tooltip-classic"><span class="tooltip-classic-item"><span class="tooltip-classic-content"><span class="tooltip-classic-text">