Bytes Route – Digital Adoption Platform Security & Risk Analysis

wordpress.org/plugins/bytes-route-digital-adoption-platform

Create engaging web product tours in minutes without coding or cookies. Increase user satisfaction and retention. Start for free with Bytes Route.

0 active installs v2.0.0 PHP 7.4+ WP 4.9.0+ Updated Feb 24, 2025
onboardingproduct-tourstooltipuser-onboardingwalkthrough
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bytes Route – Digital Adoption Platform Safe to Use in 2026?

Generally Safe

Score 92/100

Bytes Route – Digital Adoption Platform has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "bytes-route-digital-adoption-platform" v2.0.0 plugin exhibits a generally strong security posture based on the static analysis. The complete absence of identified AJAX handlers, REST API routes, shortcodes, and cron events with exposed attack surfaces is a significant positive. Furthermore, the code demonstrates a commitment to secure practices by utilizing prepared statements for all SQL queries and avoiding file operations and external HTTP requests. This indicates a deliberate effort to minimize common vulnerabilities.

However, some areas warrant attention. While the total number of output escapes is reasonable, a notable portion (27%) are not properly escaped, representing a potential risk for cross-site scripting (XSS) vulnerabilities if user-controlled data is directly outputted. The taint analysis revealing two flows with unsanitized paths, although not flagged as critical or high severity, still suggests that input validation or sanitization might be insufficient in certain contexts. The lack of any recorded vulnerability history, while seemingly positive, could also indicate that the plugin hasn't been subjected to extensive security testing or that vulnerabilities have gone unnoticed or unreported. The absence of nonce and capability checks on the limited entry points that do exist is also a weakness.

In conclusion, the plugin has several fundamental security strengths, particularly in its minimal attack surface and secure SQL handling. Nevertheless, the unescaped output and potential issues highlighted by the taint analysis, coupled with the absence of explicit authorization checks on the limited entry points, suggest that further investigation and hardening of specific code paths are advisable to achieve a truly robust security profile. The vulnerability history, or lack thereof, should not be interpreted as a guarantee of absolute security.

Key Concerns

  • Unescaped output detected
  • Flows with unsanitized paths
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Bytes Route – Digital Adoption Platform Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Bytes Route – Digital Adoption Platform Release Timeline

v2.0.0Current
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Bytes Route – Digital Adoption Platform Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
11 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

73% escaped15 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
generate_bytesroutedotcom_settings_page (bytes-route.php:59)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Bytes Route – Digital Adoption Platform Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menubytes-route.php:45
actionwp_headbytes-route.php:196
actionadmin_headbytes-route.php:209
actionlogin_footerbytes-route.php:223
Maintenance & Trust

Bytes Route – Digital Adoption Platform Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 24, 2025
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Bytes Route – Digital Adoption Platform Developer Profile

bytesroute

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bytes Route – Digital Adoption Platform

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
brt-script
FAQ

Frequently Asked Questions about Bytes Route – Digital Adoption Platform