
UXsniff AI-powered Heatmaps and Session Recordings Security & Risk Analysis
wordpress.org/plugins/ux-sniffShort Description: AI-powered Heatmaps, Session Recordings & A/B Testing
Is UXsniff AI-powered Heatmaps and Session Recordings Safe to Use in 2026?
Mostly Safe
Score 78/100UXsniff AI-powered Heatmaps and Session Recordings is generally safe to use. 1 past CVE were resolved. Keep it updated.
The 'ux-sniff' plugin v1.3.3 exhibits a mixed security posture. On the positive side, the static analysis reveals a limited attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are accessible without authentication. Furthermore, all SQL queries are properly prepared, indicating good database interaction practices. However, a significant concern arises from the taint analysis, which shows that all analyzed flows have unsanitized paths, although no critical or high severity issues were flagged. The plugin's vulnerability history is also a major red flag, with one currently unpatched medium severity CVE for Cross-Site Scripting, which last occurred on April 10, 2025. This historical pattern, combined with a low percentage of properly escaped output (15%), suggests a recurring weakness in handling user-provided data, making it susceptible to XSS attacks if the unpatched CVE is exploited or if similar vulnerabilities exist and are not yet publicly known.
Key Concerns
- Currently unpatched CVE (Medium)
- All analyzed taint flows have unsanitized paths
- Low output escaping rate (15%)
- Bundled DataTables library
UXsniff AI-powered Heatmaps and Session Recordings Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
UXsniff <= 1.2.8 - Reflected Cross-Site Scripting
UXsniff AI-powered Heatmaps and Session Recordings Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
UXsniff AI-powered Heatmaps and Session Recordings Attack Surface
WordPress Hooks 6
Maintenance & Trust
UXsniff AI-powered Heatmaps and Session Recordings Maintenance & Trust
Maintenance Signals
Community Trust
UXsniff AI-powered Heatmaps and Session Recordings Alternatives
Lucky Orange
lucky-orange
Less time crunching numbers, more time growing your business.
Hotjar
hotjar
The fast & visual way to understand your users.
Unbounce Landing Pages
unbounce
Unbounce is the most powerful standalone landing page builder available.
Mouseflow for WordPress
mouseflow-for-wordpress
Mouseflow gives you free and easy-to-use conversion and user experience analytics for your website. Analyze conversion funnels, heatmaps and even sess …
Instapage Plugin
instapage
Instapage plugin - the best way for WordPress to seamlessly publish landing pages as a natural extension of your WordPress blog or website.
UXsniff AI-powered Heatmaps and Session Recordings Developer Profile
2 plugins · 100 total installs
How We Detect UXsniff AI-powered Heatmaps and Session Recordings
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ux-sniff/style.css/wp-content/plugins/ux-sniff/assets/css/main.css/wp-content/plugins/ux-sniff/assets/css/dataTables.bootstrap.min.css/wp-content/plugins/ux-sniff/assets/css/responsive.bootstrap.min.css/wp-content/plugins/ux-sniff/assets/css/fixedHeader.dataTables.min.css/wp-content/plugins/ux-sniff/assets/css/daterangepicker.css/wp-content/plugins/ux-sniff/assets/css/bootstrap.min.css/wp-content/plugins/ux-sniff/assets/js/global.min.js+4 moreux-sniff/style.css?ver=ux-sniff/assets/css/main.css?ver=ux-sniff/assets/css/dataTables.bootstrap.min.css?ver=ux-sniff/assets/css/responsive.bootstrap.min.css?ver=ux-sniff/assets/css/fixedHeader.dataTables.min.css?ver=ux-sniff/assets/css/daterangepicker.css?ver=ux-sniff/assets/css/bootstrap.min.css?ver=ux-sniff/assets/js/global.min.js?ver=ux-sniff/assets/js/bootstrap.bundle.js?ver=ux-sniff/assets/js/echarts.min.js?ver=ux-sniff/assets/js/jquery.dataTables.min.js?ver=ux-sniff/assets/js/dataTables.responsive.min.js?ver=