
Tooltips for WordPress Security & Risk Analysis
wordpress.org/plugins/wordpress-tooltipsAdd custom tooltip automatically for post's content/title/tag/excerpt/gallery/menu, easily add image / video / audio / social/link tooltips
Is Tooltips for WordPress Safe to Use in 2026?
Use With Caution
Score 64/100Tooltips for WordPress has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The wordpress-tooltips plugin version 10.9.3 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and implementing a substantial number of nonce and capability checks. The static analysis indicates no directly exposed AJAX handlers or REST API routes without authentication, and the taint analysis did not reveal critical or high severity unsanitized flows.
However, significant concerns arise from its vulnerability history. The presence of four known CVEs, with one still unpatched and classified as critical, is a major red flag. The historical vulnerability types, including Cross-Site Scripting, CSRF, and SQL Injection, suggest recurring patterns of insecure input handling and authentication weaknesses. Furthermore, the static analysis highlights that only 46% of output is properly escaped, which, despite the absence of critical taint flows, leaves room for potential stored XSS vulnerabilities, especially when combined with the plugin's history of XSS issues.
In conclusion, while the plugin has strengths in its adherence to secure SQL practices and some authentication mechanisms, the unpatched critical vulnerability and the historical trend of critical vulnerability types necessitate immediate attention. The partial output escaping is also a risk that should be addressed to prevent potential XSS attacks.
Key Concerns
- Unpatched critical CVE
- Bundled outdated jQuery v1.3.2
- 46% of output properly escaped
- History of critical/medium vulnerabilities (XSS, SQLi, CSRF)
Tooltips for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Tooltips <= 10.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
WordPress Tooltips <= 9.4.9 - Cross-Site Request Forgery
WordPress Tooltips <= 9.4.3 - Authenticated (Contributor+) SQL Injection
WordPress Tooltips <= 8.2.5 - Multiple Cross-Site Request Forgery
Tooltips for WordPress Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Tooltips for WordPress Attack Surface
Shortcodes 13
WordPress Hooks 58
Maintenance & Trust
Tooltips for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Tooltips for WordPress Alternatives
CM Tooltip Glossary
enhanced-tooltipglossary
Transform jargon into engaging content that boosts SEO, drives engagement, improves conversions, with automatic links and tooltips.
Glossary
glossary-by-codeat
Boost your SEO & UX with Codeat's Glossary: powerful auto-link engine; customizable tooltips, mobile settings, ChatGPT and much more!
Tooltipy (tooltips for WP)
bluet-keywords-tooltip-generator
Tooltipy allows you to highlight the keywords in your content in order to show a responsive description tooltips
Image Hotspot Block
image-hotspot-block
Create dynamic images with clickable hotspots to showcase products. Optimized for WooCommerce.
Glossary Tooltip – Build a Smart Knowledge Base with Tooltips
glossary-tooltip
Create a powerful glossary knowledge base to boost SEO, increase engagement, improve conversions with automatic links and tooltips.
Tooltips for WordPress Developer Profile
10 plugins · 7K total installs
How We Detect Tooltips for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wordpress-tooltips/css/tooltips.css/wp-content/plugins/wordpress-tooltips/css/font-awesome.min.css/wp-content/plugins/wordpress-tooltips/css/jquery-ui.css/wp-content/plugins/wordpress-tooltips/css/bootstrap.min.css/wp-content/plugins/wordpress-tooltips/css/toastr.css/wp-content/plugins/wordpress-tooltips/js/jquery.min.js/wp-content/plugins/wordpress-tooltips/js/jquery-ui.min.js/wp-content/plugins/wordpress-tooltips/js/bootstrap.min.js+8 morewordpress-tooltips/css/tooltips.css?ver=wordpress-tooltips/css/font-awesome.min.css?ver=wordpress-tooltips/css/jquery-ui.css?ver=wordpress-tooltips/css/bootstrap.min.css?ver=wordpress-tooltips/css/toastr.css?ver=wordpress-tooltips/js/jquery.min.js?ver=wordpress-tooltips/js/jquery-ui.min.js?ver=wordpress-tooltips/js/bootstrap.min.js?ver=wordpress-tooltips/js/toastr.js?ver=wordpress-tooltips/js/tooltips.js?ver=wordpress-tooltips/js/tooltipster.bundle.min.js?ver=wordpress-tooltips/js/owl.carousel.min.js?ver=wordpress-tooltips/js/tinymce/tinymce.min.js?ver=wordpress-tooltips/js/colorpicker.js?ver=wordpress-tooltips/js/tooltips-admin.js?ver=wordpress-tooltips/js/clipboard.min.js?ver=HTML / DOM Fingerprints
tooltipster-basetooltipster-boxtooltipster-contenttooltipster-shadowtooltipster-arrowtooltipster-arrow-outertt-tooltip-contenttt-tooltip-title<!-- 8.1.9 --><!-- 8.3.3 --><!--9.1.7 --><!--9.4.3 -->+8 moredata-tooltip-iddata-tooltip-titledata-tooltip-contentdata-tooltip-themedata-tooltip-positiondata-tooltip-trigger+21 moretooltips_paramsTooltipsAdmin[tooltips][/tooltips][tooltipster][/tooltipster]