Usetiful – Digital Adoption Platform Security & Risk Analysis

wordpress.org/plugins/usetiful-digital-adoption-platform

Fight user churn with great user onboarding! Interactive product tours, smart tips and user onboarding checklists for digital products

100 active installs v1.6 PHP + WP 4.9.0+ Updated May 25, 2025
onboardingtooltipuser-onboardinguxwalkthrough
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Usetiful – Digital Adoption Platform Safe to Use in 2026?

Generally Safe

Score 100/100

Usetiful – Digital Adoption Platform has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "usetiful-digital-adoption-platform" v1.6 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, file operations, or external HTTP requests is highly commendable. Furthermore, the plugin has no recorded vulnerability history, indicating a clean past and potentially robust development practices.

However, a significant concern arises from the output escaping analysis, where only 44% of outputs are properly escaped. This suggests a potential for Cross-Site Scripting (XSS) vulnerabilities, where user-supplied data, if not properly sanitized before being displayed, could be exploited by attackers to inject malicious scripts. While the plugin has a nonce check, the lack of capability checks and the complete absence of identified taint flows are curious; the low percentage of proper output escaping implies there *should* be opportunities for taint to be discovered if it existed. The small attack surface with no unprotected entry points is a positive indicator, but the output escaping issue is a notable weakness that requires attention.

In conclusion, while the plugin demonstrates strengths in areas like avoiding dangerous functions and maintaining a clean vulnerability history, the insufficient output escaping is a critical area of concern that significantly lowers its overall security score. Addressing this would greatly improve the plugin's resilience against common web attacks. The lack of reported taint flows is unusual given the output escaping issues, which might indicate the test coverage was limited or that the specific paths leading to unsanitized output are not easily discoverable by the static analysis tools used.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

Usetiful – Digital Adoption Platform Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Usetiful – Digital Adoption Platform Release Timeline

v1.6Current
v1.5
v1.1
Code Analysis
Analyzed Mar 16, 2026

Usetiful – Digital Adoption Platform Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
33
26 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

44% escaped59 total outputs
Attack Surface

Usetiful – Digital Adoption Platform Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_menuusetiful.php:47
actionwp_footerusetiful.php:49
actionadmin_footerusetiful.php:50
actionadmin_enqueue_scriptsusetiful.php:51
actionadmin_enqueue_scriptsusetiful.php:52
filterusetiful_get_tags_name_filterusetiful.php:54
filterusetiful_get_wp_tags_filterusetiful.php:55
filterusetiful_add_wp_tags_filterusetiful.php:57
Maintenance & Trust

Usetiful – Digital Adoption Platform Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 25, 2025
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Usetiful – Digital Adoption Platform Developer Profile

usetiful

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Usetiful – Digital Adoption Platform

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/usetiful-digital-adoption-platform/assets/css/usetiful_style.css/wp-content/plugins/usetiful-digital-adoption-platform/assets/js/usetiful_script.js
Script Paths
/wp-content/plugins/usetiful-digital-adoption-platform/assets/js/usetiful_script.js
Version Parameters
usetiful_styleusetiful_script

HTML / DOM Fingerprints

CSS Classes
usetiful-contentusetiful-settingusetiful-submit-sectionusetiful-submit
Data Attributes
usetiful-settings-submit
JS Globals
usetiful_args
FAQ

Frequently Asked Questions about Usetiful – Digital Adoption Platform