
Image Hotspot With Tooltip For WPBakery Page Builder (formerly Visual Composer) Security & Risk Analysis
wordpress.org/plugins/vc-image-hotspotCheckout our Latest WordPress Themes - 100% Free
Is Image Hotspot With Tooltip For WPBakery Page Builder (formerly Visual Composer) Safe to Use in 2026?
Generally Safe
Score 85/100Image Hotspot With Tooltip For WPBakery Page Builder (formerly Visual Composer) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The vc-image-hotspot plugin, version 1.2.0, exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, properly escaped output, and the exclusive use of prepared statements for SQL queries are excellent security practices. The plugin also demonstrates no file operations or external HTTP requests, further reducing potential attack vectors. The presence of a capability check, albeit only one, is a positive sign of basic authorization, and the limited attack surface with no unprotected entry points is commendable.
However, a significant concern arises from the lack of any nonce checks. While the static analysis indicates no unprotected entry points, this could be due to the single capability check covering the shortcode. In a real-world scenario, shortcodes can sometimes be triggered in ways that bypass direct user interaction or require more granular protection. The complete absence of taint analysis results is also noted; ideally, a more thorough analysis would yield some data, even if it indicates no critical issues. The lack of any recorded vulnerabilities in its history is a positive indicator, suggesting a history of secure development, but it doesn't guarantee future security.
In conclusion, the plugin appears to be developed with a good understanding of core WordPress security principles. The primary weakness lies in the absence of nonces, which is a standard security measure for protecting against CSRF attacks, especially for functionality that might involve user-initiated actions. The limited attack surface and absence of known vulnerabilities are strengths, but the lack of nonce checks prevents a perfect score.
Key Concerns
- Missing nonce checks
Image Hotspot With Tooltip For WPBakery Page Builder (formerly Visual Composer) Security Vulnerabilities
Image Hotspot With Tooltip For WPBakery Page Builder (formerly Visual Composer) Code Analysis
Output Escaping
Image Hotspot With Tooltip For WPBakery Page Builder (formerly Visual Composer) Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Image Hotspot With Tooltip For WPBakery Page Builder (formerly Visual Composer) Maintenance & Trust
Maintenance Signals
Community Trust
Image Hotspot With Tooltip For WPBakery Page Builder (formerly Visual Composer) Alternatives
Mega Addons For WPBakery Page Builder
mega-addons-for-visual-composer
34+ Addons WPBakery extension, Beautifully designed unique elements, Includes Premium quality addons For WPBakery Page Builder.
Amazing Hover Effects for WPBakery Page Builder
amazing-hover-effects-for-wpbakery-page-builder
Checkout our Latest WordPress Themes - 100% Free
Flipbox Addon for WPBakery Page Builder (formerly Visual Composer)
vc-flipbox
Checkout our Latest WordPress Themes - 100% Free
Hover Effects For Visual Composer
hover-effects-for-visual-composer
Checkout our Latest WordPress Themes - 100% Free
WPBakery Page Builder Addons by Livemesh
addons-for-visual-composer
A collection of 25+ beautifully designed premium quality addons or extensions for WPBakery Page Builder.
Image Hotspot With Tooltip For WPBakery Page Builder (formerly Visual Composer) Developer Profile
13 plugins · 1K total installs
How We Detect Image Hotspot With Tooltip For WPBakery Page Builder (formerly Visual Composer)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/vc-image-hotspot/admin/admin.css/wp-content/plugins/vc-image-hotspot/admin/jquery.hotspot.js/wp-content/plugins/vc-image-hotspot/admin/hotspot.css/wp-content/plugins/vc-image-hotspot/admin/jquery.hotspot.jsvc-image-hotspot/admin/admin.css?ver=vc-image-hotspot/admin/jquery.hotspot.js?ver=vc-image-hotspot/admin/hotspot.css?ver=HTML / DOM Fingerprints
ihwt_hotspot_iconihwt-vc-tiphvc_notice<!-- To get all features working, please buy the pro version here data-balloon-lengthdata-balloondata-balloon-pos