Image Hotspot With Tooltip For WPBakery Page Builder (formerly Visual Composer) Security & Risk Analysis

wordpress.org/plugins/vc-image-hotspot

Checkout our Latest WordPress Themes - 100% Free

400 active installs v1.2.0 PHP + WP 4.0.1+ Updated Jul 26, 2021
addonimage-hotspottooltipvisual-composerwpbakery-page-builder
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Image Hotspot With Tooltip For WPBakery Page Builder (formerly Visual Composer) Safe to Use in 2026?

Generally Safe

Score 85/100

Image Hotspot With Tooltip For WPBakery Page Builder (formerly Visual Composer) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The vc-image-hotspot plugin, version 1.2.0, exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, properly escaped output, and the exclusive use of prepared statements for SQL queries are excellent security practices. The plugin also demonstrates no file operations or external HTTP requests, further reducing potential attack vectors. The presence of a capability check, albeit only one, is a positive sign of basic authorization, and the limited attack surface with no unprotected entry points is commendable.

However, a significant concern arises from the lack of any nonce checks. While the static analysis indicates no unprotected entry points, this could be due to the single capability check covering the shortcode. In a real-world scenario, shortcodes can sometimes be triggered in ways that bypass direct user interaction or require more granular protection. The complete absence of taint analysis results is also noted; ideally, a more thorough analysis would yield some data, even if it indicates no critical issues. The lack of any recorded vulnerabilities in its history is a positive indicator, suggesting a history of secure development, but it doesn't guarantee future security.

In conclusion, the plugin appears to be developed with a good understanding of core WordPress security principles. The primary weakness lies in the absence of nonces, which is a standard security measure for protecting against CSRF attacks, especially for functionality that might involve user-initiated actions. The limited attack surface and absence of known vulnerabilities are strengths, but the lack of nonce checks prevents a perfect score.

Key Concerns

  • Missing nonce checks
Vulnerabilities
None known

Image Hotspot With Tooltip For WPBakery Page Builder (formerly Visual Composer) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Image Hotspot With Tooltip For WPBakery Page Builder (formerly Visual Composer) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
17 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped17 total outputs
Attack Surface

Image Hotspot With Tooltip For WPBakery Page Builder (formerly Visual Composer) Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[ihwt_hotspot] hotspot.php:160
WordPress Hooks 3
actionadmin_enqueue_scriptsvc-image-hotspot.php:36
actionadmin_noticesvc-image-hotspot.php:48
actionadmin_initvc-image-hotspot.php:58
Maintenance & Trust

Image Hotspot With Tooltip For WPBakery Page Builder (formerly Visual Composer) Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedJul 26, 2021
PHP min version
Downloads19K

Community Trust

Rating40/100
Number of ratings4
Active installs400
Developer Profile

Image Hotspot With Tooltip For WPBakery Page Builder (formerly Visual Composer) Developer Profile

themebon

13 plugins · 1K total installs

82
trust score
Avg Security Score
83/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Image Hotspot With Tooltip For WPBakery Page Builder (formerly Visual Composer)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vc-image-hotspot/admin/admin.css/wp-content/plugins/vc-image-hotspot/admin/jquery.hotspot.js/wp-content/plugins/vc-image-hotspot/admin/hotspot.css
Script Paths
/wp-content/plugins/vc-image-hotspot/admin/jquery.hotspot.js
Version Parameters
vc-image-hotspot/admin/admin.css?ver=vc-image-hotspot/admin/jquery.hotspot.js?ver=vc-image-hotspot/admin/hotspot.css?ver=

HTML / DOM Fingerprints

CSS Classes
ihwt_hotspot_iconihwt-vc-tiphvc_notice
HTML Comments
<!-- To get all features working, please buy the pro version here
Data Attributes
data-balloon-lengthdata-balloondata-balloon-pos
FAQ

Frequently Asked Questions about Image Hotspot With Tooltip For WPBakery Page Builder (formerly Visual Composer)