
Digital Humans Security & Risk Analysis
wordpress.org/plugins/digital-humansUNITH Digital Humans are personalized, real-time conversational assistants. Use this plugin to add a UNITH Digital Human to your website.
Is Digital Humans Safe to Use in 2026?
Generally Safe
Score 92/100Digital Humans has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'digital-humans' v1.0.16 demonstrates a generally strong security posture based on the provided static analysis. The absence of known vulnerabilities and CVEs in its history is a significant positive indicator, suggesting a history of responsible development and patching. The code analysis also reveals good security practices such as the exclusive use of prepared statements for SQL queries and a very high percentage of properly escaped output. The minimal attack surface of two AJAX handlers, both with nonce checks, further contributes to a positive assessment.
However, there are areas for concern. The most notable is the complete lack of capability checks for the identified AJAX handlers. While nonce checks help prevent Cross-Site Request Forgery (CSRF) attacks, they do not authenticate or authorize the user performing the action. This means any user, regardless of their WordPress role or permissions, could potentially trigger these AJAX actions, which could lead to unauthorized operations if the functionality of these handlers is sensitive. The presence of a file operation without further context also warrants caution, as file operations can be a source of vulnerabilities if not handled with extreme care.
In conclusion, the plugin exhibits strong technical security measures in its handling of data and output. The clean vulnerability history is reassuring. The primary weakness lies in the insufficient authorization checks for its entry points, creating a potential security gap. Addressing the lack of capability checks on AJAX handlers would significantly bolster the plugin's security.
Key Concerns
- AJAX handlers without capability checks
- File operation without detailed context
Digital Humans Security Vulnerabilities
Digital Humans Code Analysis
Output Escaping
Digital Humans Attack Surface
AJAX Handlers 2
WordPress Hooks 6
Maintenance & Trust
Digital Humans Maintenance & Trust
Maintenance Signals
Community Trust
Digital Humans Alternatives
AI Chatbot – Jotform
jotform-ai-chatbot
AI chatbot that automates support, answers FAQs, drives WooCommerce sales, generates leads, and boosts engagement — easy setup, no coding!
Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System
support-genix-lite
Manage customer support with a powerful helpdesk & support ticket system — track customer tickets, resolve, and streamline your support workflow.
AI Chat App – Live Agent Handover, Help Docs, Email, Call Button, Fast Support
help-dialog
Improve customer support with AI chat, live agent handover, FAQs, search, and contact form. Cut support tickets by 50% or more while boosting sales.
ChatLab – AI Chatbot for WordPress and WooCommerce
chatlab-ai-chatbot-for-your-website-gpt-powered-customer-sales-assistant
ChatLab is an AI chatbot for WordPress that learns from your website content and answers visitor questions about your services and pages.
Desku.io – Live Chat, Help Desk & Knowledge Base
desku-livechat-ai-chatbot
AI customer service software for WordPress—live chat, instant replies & a smart knowledge base to boost support in minutes.
Digital Humans Developer Profile
1 plugin · 10 total installs
How We Detect Digital Humans
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/digital-humans/front/digitalhumans.js/wp-content/plugins/digital-humans/front/iframe.txt/wp-content/plugins/digital-humans/front/digitalhumans.jsdigitalhumans.js?ver=action=digitalhumans&version=HTML / DOM Fingerprints
full-screen-buttoncontrols buttonmsgs-containerdata-api_basedata-message_feedbackdata-mic_enableddata-subs_enableddata-themedata-language+7 more<iframe id="digitalhumans-iframe" style="border:none;width:1px;height:1px" src="