TP Product Tooltip for WooCommerce Security & Risk Analysis

wordpress.org/plugins/tp-product-tooltip

Increase your sales by adding beautiful designed Tooltip to your woocommerce products.

10 active installs v1.0.4 PHP + WP 4.5+ Updated Dec 31, 2021
product-tooltiptooltipwoocommerce-product-tooltipwoocommerce-tooltip
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TP Product Tooltip for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

TP Product Tooltip for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The 'tp-product-tooltip' v1.0.4 plugin presents a mixed security posture. While it boasts zero known CVEs and no apparent critical taint flows or dangerous functions, its static analysis reveals significant areas of concern. The plugin has a total of one entry point, an AJAX handler, which lacks any authentication or authorization checks. This is a major weakness, exposing a potentially sensitive function to unauthorized access and exploitation. Furthermore, the plugin demonstrates poor output escaping practices, with only 18% of its outputs being properly sanitized. This significantly increases the risk of cross-site scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed in the context of a user's browser.

The absence of vulnerability history suggests a lack of past exploitation or discovery, which is a positive indicator. However, the current code analysis highlights critical security flaws that could be actively exploited regardless of historical data. The lack of nonce checks and capability checks on the unprotected AJAX handler are particularly worrying. In conclusion, while the plugin has a clean vulnerability history and avoids common pitfalls like raw SQL or bundled libraries, the unprotected AJAX endpoint and pervasive unescaped output create substantial security risks that require immediate attention.

Key Concerns

  • Unprotected AJAX handler
  • Low percentage of properly escaped output
  • Missing nonce checks on AJAX
  • Missing capability checks on AJAX
Vulnerabilities
None known

TP Product Tooltip for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

TP Product Tooltip for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
53
12 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

18% escaped65 total outputs
Attack Surface
1 unprotected

TP Product Tooltip for WooCommerce Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_tpwpt_rest_api_ajaxincludes\class-tp-woocommerce-product-tooltip.php:172
WordPress Hooks 23
actionplugins_loadedincludes\class-tp-woocommerce-product-tooltip.php:142
actionadmin_enqueue_scriptsincludes\class-tp-woocommerce-product-tooltip.php:157
actionadmin_enqueue_scriptsincludes\class-tp-woocommerce-product-tooltip.php:158
actionadmin_menuincludes\class-tp-woocommerce-product-tooltip.php:160
filterplugin_row_metaincludes\class-tp-woocommerce-product-tooltip.php:163
filterwoocommerce_product_data_tabsincludes\class-tp-woocommerce-product-tooltip.php:167
actionwoocommerce_product_data_panelsincludes\class-tp-woocommerce-product-tooltip.php:168
actionwoocommerce_process_product_metaincludes\class-tp-woocommerce-product-tooltip.php:169
actionwp_enqueue_scriptsincludes\class-tp-woocommerce-product-tooltip.php:187
actionwp_enqueue_scriptsincludes\class-tp-woocommerce-product-tooltip.php:188
actionwpincludes\class-tp-woocommerce-product-tooltip.php:192
actionwoocommerce_before_shop_loop_itemincludes\class-tp-woocommerce-product-tooltip.php:196
actionwoocommerce_before_main_contentpublic\class-tp-woocommerce-product-tooltip-public.php:438
actionwoocommerce_before_single_productpublic\class-tp-woocommerce-product-tooltip-public.php:442
actionwoocommerce_before_single_product_summarypublic\class-tp-woocommerce-product-tooltip-public.php:446
actionwoocommerce_single_product_summarypublic\class-tp-woocommerce-product-tooltip-public.php:452
actionwoocommerce_single_product_summarypublic\class-tp-woocommerce-product-tooltip-public.php:459
actionwoocommerce_single_product_summarypublic\class-tp-woocommerce-product-tooltip-public.php:463
actionwoocommerce_single_product_summarypublic\class-tp-woocommerce-product-tooltip-public.php:468
actionwoocommerce_single_product_summarypublic\class-tp-woocommerce-product-tooltip-public.php:478
actionwoocommerce_after_single_product_summarypublic\class-tp-woocommerce-product-tooltip-public.php:482
actionwoocommerce_after_single_product_summarypublic\class-tp-woocommerce-product-tooltip-public.php:486
actionwoocommerce_before_single_product_summarypublic\class-tp-woocommerce-product-tooltip-public.php:489
Maintenance & Trust

TP Product Tooltip for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedDec 31, 2021
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

TP Product Tooltip for WooCommerce Developer Profile

Payment Plugins

65 plugins · 296K total installs

85
trust score
Avg Security Score
96/100
Avg Patch Time
88 days
View full developer profile
Detection Fingerprints

How We Detect TP Product Tooltip for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tp-product-tooltip/admin/css/tp-woocommerce-product-tooltip-admin.css/wp-content/plugins/tp-product-tooltip/admin/css/jquery.tp_tooltip_minicolors.css/wp-content/plugins/tp-product-tooltip/admin/js/jquery.tp_tooltip_minicolors.min.js/wp-content/plugins/tp-product-tooltip/admin/js/tp-woocommerce-product-tooltip-admin.js/wp-content/plugins/tp-product-tooltip/admin/js/tpwpt-ajax-core-admin.js
Script Paths
admin/js/jquery.tp_tooltip_minicolors.min.jsadmin/js/tp-woocommerce-product-tooltip-admin.jsadmin/js/tpwpt-ajax-core-admin.js
Version Parameters
tp-woocommerce-product-tooltip-admin.css?ver=jquery.tp_tooltip_minicolors.css?ver=jquery.tp_tooltip_minicolors.min.js?ver=tp-woocommerce-product-tooltip-admin.js?ver=tpwpt-ajax-core-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
tp-tooltip-wrappertp-tooltip-contenttp-tooltip-arrowtp-tooltip-visibletp-tooltip-active
HTML Comments
<!-- START TP Product Tooltip --><!-- END TP Product Tooltip --><!-- TP Tooltip Content Start --><!-- TP Tooltip Content End -->+2 more
Data Attributes
data-tp-tooltipdata-tp-tooltip-positiondata-tp-tooltip-animationdata-tp-tooltip-delay
JS Globals
tpwptParam
REST Endpoints
/wp-json/tp-product-tooltip/v1/get_product_data
Shortcode Output
[tp_product_tooltip[tp_product_tooltip_category
FAQ

Frequently Asked Questions about TP Product Tooltip for WooCommerce