Usersnap Security & Risk Analysis

wordpress.org/plugins/usersnap

Usersnap: The feedback platform designed to capture, organize, and respond to user feedback seamlessly.

500 active installs v4.20 PHP + WP 3.0+ Updated Jun 26, 2024
browser-screenshot-toolbug-tracking-toolscreen-recording-feedbackuser-acceptance-testing-toolwebsite-feedback-tool
92
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 2, 2023
Safety Verdict

Is Usersnap Safe to Use in 2026?

Generally Safe

Score 92/100

Usersnap has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Feb 2, 2023Updated 1yr ago
Risk Assessment

The "usersnap" plugin v4.20 presents a mixed security posture. While the static analysis indicates a generally good practice with zero identified dangerous functions, SQL injection vulnerabilities, or file operations, and all SQL queries utilizing prepared statements, there are notable weaknesses. The low percentage of properly escaped output (10%) is a significant concern, suggesting a high potential for cross-site scripting (XSS) vulnerabilities. The absence of nonce checks on AJAX handlers and capability checks on REST API routes, coupled with zero identified entry points and unprotected handlers, might indicate a limited attack surface or that these checks are handled elsewhere, but it also means any future introduced entry points could be unprotected.

The vulnerability history reveals one past medium-severity vulnerability, specifically Cross-site Scripting, which was patched in early 2023. While there are no currently unpatched CVEs, the historical presence of XSS suggests that the development team may have had challenges in properly sanitizing output in the past. This, combined with the current static analysis findings of poor output escaping, points to a recurring area of risk that requires careful monitoring and more robust sanitization practices.

In conclusion, the plugin demonstrates strengths in its avoidance of common injection vulnerabilities and secure SQL handling. However, the significant concern regarding insufficient output escaping, supported by past XSS vulnerabilities, presents a tangible risk. The limited attack surface revealed in the static analysis is a positive sign, but the potential for XSS due to poor output handling remains the most critical weakness.

Key Concerns

  • Low percentage of properly escaped output
  • Past medium CVE (XSS)
  • No nonce checks on AJAX handlers
  • No permission callbacks on REST API routes
Vulnerabilities
1

Usersnap Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2022-47607medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Usersnap <= 4.16 - Authenticated (Admin+) Stored Cross Site Scripting

Feb 2, 2023 Patched in 4.17 (355d)
Code Analysis
Analyzed Mar 16, 2026

Usersnap Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
18
2 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

10% escaped20 total outputs
Attack Surface

Usersnap Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_initusersnap.php:17
actionadmin_menuusersnap.php:18
actionadmin_headusersnap.php:19
actionwp_headusersnap.php:21
actionadmin_enqueue_scriptsusersnap.php:494
actionadmin_print_footer_scriptsusersnap.php:498
Maintenance & Trust

Usersnap Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedJun 26, 2024
PHP min version
Downloads57K

Community Trust

Rating82/100
Number of ratings7
Active installs500
Alternatives

Usersnap Alternatives

No alternatives data available yet.

Developer Profile

Usersnap Developer Profile

Usersnap

1 plugin · 500 total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
355 days
View full developer profile
Detection Fingerprints

How We Detect Usersnap

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/usersnap/style.css
Version Parameters
usersnap/style.css?ver=usersnap.php?ver=

HTML / DOM Fingerprints

CSS Classes
us-box
Data Attributes
data-cfasync
JS Globals
window['_usersnapconfig']
FAQ

Frequently Asked Questions about Usersnap