WP Image Markers – Easy Hotspot Solution Security & Risk Analysis

wordpress.org/plugins/wp-image-makers-easy-hotspot-solution

Easy way to add markers to an image and drag to reposition them.

800 active installs v1.0.0 PHP + WP 4.5+ Updated Mar 8, 2018
hotspotimageimage-hotspotsimage-mapimage-marker
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Image Markers – Easy Hotspot Solution Safe to Use in 2026?

Generally Safe

Score 85/100

WP Image Markers – Easy Hotspot Solution has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The wp-image-makers-easy-hotspot-solution plugin, version 1.0.0, exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by not utilizing dangerous functions, avoiding raw SQL queries, and performing file operations or external HTTP requests. It also includes a reasonable number of nonce and capability checks. However, the presence of two unprotected AJAX handlers represents a significant concern, creating a substantial attack surface. The taint analysis shows no critical or high severity unsanitized flows, which is encouraging, but the limited scope of analysis (only 2 flows) means this doesn't completely mitigate the risk from the unprotected entry points.

The plugin's vulnerability history is clean, with no recorded CVEs. This suggests a potentially well-developed or less targeted plugin, but it's important to note that a lack of past vulnerabilities does not guarantee future security, especially given the identified unprotected AJAX handlers. The primary weakness lies in the direct exposure of AJAX functionality without proper authentication or authorization checks, which could allow for unauthorized actions if these handlers are exploitable. While the code signals for output escaping are decent, the unprotected AJAX handlers remain the most prominent risk.

Key Concerns

  • Unprotected AJAX handlers
  • Large attack surface without auth checks
  • Limited taint analysis scope
Vulnerabilities
None known

WP Image Markers – Easy Hotspot Solution Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Image Markers – Easy Hotspot Solution Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
26
59 escaped
Nonce Checks
3
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

69% escaped85 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
save (includes\Admin\Metabox.php:178)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

WP Image Markers – Easy Hotspot Solution Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_wpim_autocomplete_post_typeincludes\helpers.php:168
authwp_ajax_wpim_autocomplete_taxonomyincludes\helpers.php:169
WordPress Hooks 8
actionadd_meta_boxesincludes\Admin\Metabox.php:48
actioninitincludes\Admin\PostType.php:9
actionadd_meta_boxesincludes\Admin\PostType.php:10
actionsave_post_wp_image_markersincludes\Admin\PostType.php:11
actionwp_enqueue_scriptsincludes\EnqueueScripts.php:11
actionadmin_enqueue_scriptsincludes\EnqueueScripts.php:12
filterthe_editor_contentincludes\Field\TextareaHtmlControl.php:26
actionafter_setup_themeincludes\WPIM.php:57
Maintenance & Trust

WP Image Markers – Easy Hotspot Solution Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedMar 8, 2018
PHP min version
Downloads16K

Community Trust

Rating56/100
Number of ratings5
Active installs800
Developer Profile

WP Image Markers – Easy Hotspot Solution Developer Profile

wedesignwebuild

2 plugins · 900 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Image Markers – Easy Hotspot Solution

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-image-makers-easy-hotspot-solution/assets/css/front.css/wp-content/plugins/wp-image-makers-easy-hotspot-solution/assets/css/animate.css/wp-content/plugins/wp-image-makers-easy-hotspot-solution/assets/js/front.js/wp-content/plugins/wp-image-makers-easy-hotspot-solution/assets/css/admin.css/wp-content/plugins/wp-image-makers-easy-hotspot-solution/assets/vendors/dependency/dependency.js/wp-content/plugins/wp-image-makers-easy-hotspot-solution/assets/vendors/wp-color-picker-alpha/wp-color-picker-alpha.js/wp-content/plugins/wp-image-makers-easy-hotspot-solution/assets/vendors/wp-color-picker-alpha/wp-color-picker-alpha.min.js/wp-content/plugins/wp-image-makers-easy-hotspot-solution/assets/vendors/selectize/selectize.js+5 more
Version Parameters
wp-image-makers-easy-hotspot-solution/assets/css/front.css?ver=wp-image-makers-easy-hotspot-solution/assets/js/front.js?ver=wp-image-makers-easy-hotspot-solution/assets/css/admin.css?ver=wp-image-makers-easy-hotspot-solution/assets/vendors/dependency/dependency.js?ver=wp-image-makers-easy-hotspot-solution/assets/vendors/wp-color-picker-alpha/wp-color-picker-alpha.js?ver=wp-image-makers-easy-hotspot-solution/assets/js/fields.js?ver=wp-image-makers-easy-hotspot-solution/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpim-metaboxwpim_form_rowcol-labelcol-fieldwpim_groupgroup_navgroup_item
Data Attributes
wpim_metabox_name="wpim_metabox_nonce"wpim_form_rowwpim-metaboxwpim-metabox_group_nav+1 more
JS Globals
wpim_var
Shortcode Output
[wp_image_markers id=
FAQ

Frequently Asked Questions about WP Image Markers – Easy Hotspot Solution