
WP Super Heatmap Security & Risk Analysis
wordpress.org/plugins/wp-super-heatmapThis plugin tracks user clicks and creates a heatmap for your website. All data is stored locally and no third-party service is used. Completely free!
Is WP Super Heatmap Safe to Use in 2026?
Generally Safe
Score 85/100WP Super Heatmap has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-super-heatmap v0.1.0 plugin exhibits a concerning security posture, primarily due to its unprotected AJAX endpoints and lack of output escaping. With 8 AJAX handlers identified, all of which lack authentication checks, there is a significant attack surface exposed. This means that any user, including unauthenticated ones, could potentially trigger these functionalities, leading to unintended consequences or the exploitation of underlying vulnerabilities. The absence of proper output escaping on all identified outputs further exacerbates this risk, as it opens the door to cross-site scripting (XSS) attacks. If user-supplied data is reflected directly in the output without sanitization, an attacker could inject malicious scripts that would then execute in the victim's browser.
While the plugin has no recorded vulnerability history or critical taint analysis findings, this absence of past issues should not be interpreted as a guarantee of current security. The identified code signals, particularly the lack of authorization and escaping, represent inherent weaknesses that could be leveraged by an attacker if an exploit vector is found. The plugin does have capability checks, which is a positive, but their effectiveness is undermined by the unprotected AJAX endpoints. In conclusion, the plugin has a fundamental flaw in its handling of AJAX requests and output rendering, making it a high-risk target for various attacks despite its clean vulnerability history.
Key Concerns
- 8 unprotected AJAX handlers
- 0% output escaping
- 2 SQL queries with 0% prepared statements
- 0 nonce checks on AJAX
WP Super Heatmap Security Vulnerabilities
WP Super Heatmap Code Analysis
SQL Query Safety
Output Escaping
WP Super Heatmap Attack Surface
AJAX Handlers 8
WordPress Hooks 5
Maintenance & Trust
WP Super Heatmap Maintenance & Trust
Maintenance Signals
Community Trust
WP Super Heatmap Alternatives
WP Light Heatmap
wp-light-heatmap
This plugin allows you to create a heatmap based on mouse clicks and cursor movements.
heatmap for WordPress – Realtime analytics
heatmap-for-wp
Real-time analytics and event tracking for your WordPress sites.
Heatmap & Analytics – Howuku Web Optimization
howuku
Free heatmap and analytics tool for your WordPress sites.
Aurora Heatmap
aurora-heatmap
Beautiful like an aurora! A simple WordPress heatmap that can be completed with just a plugin.
Crazy Egg
crazyegg-heatmap-tracking
The easiest, free way to add your Crazy Egg tracking script to your WordPress site. The official Crazy Egg Plugin for WordPress.
WP Super Heatmap Developer Profile
2 plugins · 310 total installs
How We Detect WP Super Heatmap
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-super-heatmap/css/wp_super_heatmap.css/wp-content/plugins/wp-super-heatmap/js/json2.js/wp-content/plugins/wp-super-heatmap/js/wp_super_heatmap_click_js.js/wp-content/plugins/wp-super-heatmap/js/wp_super_heatmap_js.js/wp-content/plugins/wp-super-heatmap/js/jquery-ibutton/lib/jquery.ibutton.min.js/wp-content/plugins/wp-super-heatmap/js/jquery-ibutton/css/jquery.ibutton.min.css/wp-content/plugins/wp-super-heatmap/js/json.js/wp-content/plugins/wp-super-heatmap/css/Aristo/Aristo.css+1 more/wp-content/plugins/wp-super-heatmap/js/json2.js/wp-content/plugins/wp-super-heatmap/js/wp_super_heatmap_click_js.js/wp-content/plugins/wp-super-heatmap/js/wp_super_heatmap_js.js/wp-content/plugins/wp-super-heatmap/js/jquery-ibutton/lib/jquery.ibutton.min.js/wp-content/plugins/wp-super-heatmap/js/json.js/wp-content/plugins/wp-super-heatmap/js/wp_super_heatmap_admin_js.jswp-super-heatmap/css/wp_super_heatmap.css?ver=wp-super-heatmap/js/json2.js?ver=wp-super-heatmap/js/wp_super_heatmap_click_js.js?ver=wp-super-heatmap/js/wp_super_heatmap_js.js?ver=wp-super-heatmap/js/jquery-ibutton/lib/jquery.ibutton.min.js?ver=wp-super-heatmap/js/jquery-ibutton/css/jquery.ibutton.min.css?ver=wp-super-heatmap/js/json.js?ver=wp-super-heatmap/css/Aristo/Aristo.css?ver=wp-super-heatmap/css/wp_super_heatmap.css?ver=wp-super-heatmap/js/wp_super_heatmap_admin_js.js?ver=HTML / DOM Fingerprints
wp_super_heatmap_admin_stylewp_super_heatmap_styleiphone_style_checkboxes_styleajaxurl<!-- Init plugin options to white list our options --><!-- Create the table in the database --><!-- Add the options for the plugin -->+4 morewp_super_heatmap_optionswp_super_heatmap_date_optionsMyAjaxwp_super_heatmap_optionswp_super_heatmap_date_optionswp_super_heatmap_add_dotwp_super_heatmap_display/wp-json/wp_super_heatmap_add_dot/wp-json/wp_super_heatmap_display