Utilitify – Supercharge Your WordPress Site With Powerpack WordPress Utilities Security & Risk Analysis

wordpress.org/plugins/utilitify

Utilitify helps you enhance & customize your WordPress site. Power pack utilities of this plugin make people's live easier

10 active installs v1.1.1 PHP 5.6.4+ WP 5.0+ Updated Mar 1, 2025
404redirectseotoolbarutilities
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Utilitify – Supercharge Your WordPress Site With Powerpack WordPress Utilities Safe to Use in 2026?

Generally Safe

Score 92/100

Utilitify – Supercharge Your WordPress Site With Powerpack WordPress Utilities has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin 'utilitify' v1.1.1 exhibits a generally strong security posture with no known historical vulnerabilities and excellent use of prepared statements for SQL queries. The complete absence of an exposed attack surface through AJAX, REST API, shortcodes, or cron events is a significant strength. However, the static analysis reveals some areas for concern. The presence of dangerous functions like 'ini_set' and 'set_time_limit' warrants careful scrutiny, as these can be misused to impact server configuration if not properly controlled. Furthermore, the output escaping is only 52% effective, indicating a notable risk of cross-site scripting (XSS) vulnerabilities where user-supplied data is displayed without proper sanitization.

The taint analysis did not identify any critical or high-severity unsanitized flows, which is positive. However, the fact that two out of four analyzed flows had unsanitized paths suggests there might be less critical but still potentially exploitable avenues if input isn't handled rigorously throughout the plugin's execution. The vulnerability history is reassuringly clean, implying a proactive development team or simply a lack of past exploitability. Despite the clean history and well-protected entry points, the issues with output escaping and the use of dangerous functions prevent an unqualified recommendation. The plugin is well-architected in terms of entry points but requires improvements in data sanitization and output handling.

Key Concerns

  • Low output escaping percentage
  • Presence of dangerous functions
  • Flows with unsanitized paths found
Vulnerabilities
None known

Utilitify – Supercharge Your WordPress Site With Powerpack WordPress Utilities Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Utilitify – Supercharge Your WordPress Site With Powerpack WordPress Utilities Release Timeline

v1.1.1Current
v1.1.0
v1.0.12
v1.0.11
v1.0.10
v1.0.9
v1.0.8
v1.0.7
v1.0.6
v1.0.5
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Utilitify – Supercharge Your WordPress Site With Powerpack WordPress Utilities Code Analysis

Dangerous Functions
4
Raw SQL Queries
0
5 prepared
Unescaped Output
47
50 escaped
Nonce Checks
3
Capability Checks
2
File Operations
2
External Requests
2
Bundled Libraries
1

Dangerous Functions Found

ini_set@ini_set( 'memory_limit', '-1' );lite/includes/Install.php:280
set_time_limit@set_time_limit( 360 );lite/includes/Install.php:284
ini_set@ini_set( 'max_execution_time', 360 );lite/includes/Install.php:285
ini_set@ini_set( 'memory_limit', $current_memory_limit );lite/includes/Install.php:317

Bundled Libraries

Freemius1.0

SQL Query Safety

100% prepared5 total queries

Output Escaping

52% escaped97 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
dismiss_admin_notice (lite/includes/Admin.php:248)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Utilitify – Supercharge Your WordPress Site With Powerpack WordPress Utilities Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 61
actionadmin_menulite/includes/Admin/Settings.php:27
filterwpsf_register_settings_kc_uflite/includes/Admin/admin-settings.php:23
actionadmin_noticeslite/includes/Feedback.php:42
filtertiny_mce_pluginslite/includes/Frontend.php:201
filterwp_resource_hintslite/includes/Frontend.php:202
filterstyle_loader_srclite/includes/Frontend.php:272
filterscript_loader_srclite/includes/Frontend.php:277
filterafter_setup_themelite/includes/Frontend.php:297
filterxmlrpc_enabledlite/includes/Frontend.php:302
filterauto_update_pluginlite/includes/Frontend.php:307
filterauto_update_themelite/includes/Frontend.php:312
actionwp_enqueue_scriptslite/includes/Frontend.php:318
actionwp_footerlite/includes/Frontend.php:323
actiondo_feedlite/includes/Frontend.php:328
actiondo_feed_rdflite/includes/Frontend.php:329
actiondo_feed_rsslite/includes/Frontend.php:330
actiondo_feed_rss2lite/includes/Frontend.php:331
actiondo_feed_atomlite/includes/Frontend.php:332
actiondo_feed_rss2_commentslite/includes/Frontend.php:333
actiondo_feed_atom_commentslite/includes/Frontend.php:334
filterthe_excerpt_rsslite/includes/Frontend.php:345
filterthe_content_feedlite/includes/Frontend.php:346
filterwidget_textlite/includes/Frontend.php:352
actionadmin_initlite/includes/Install.php:32
actionadmin_initlite/includes/Install.php:33
filterkc_uf_filter_settings_tablite/includes/Modules/Handle404.php:20
filterkc_uf_filter_settings_sectionslite/includes/Modules/Handle404.php:21
actionwplite/includes/Modules/Handle404.php:23
filterkc_uf_filter_settings_tablite/includes/Modules/Recaptcha.php:32
filterkc_uf_filter_settings_sectionslite/includes/Modules/Recaptcha.php:33
actionlogin_enqueue_scriptslite/includes/Modules/Recaptcha.php:47
actionadmin_enqueue_scriptslite/includes/Modules/Recaptcha.php:48
actionlostpassword_formlite/includes/Modules/Recaptcha.php:51
actionregister_formlite/includes/Modules/Recaptcha.php:52
actionlogin_formlite/includes/Modules/Recaptcha.php:53
actionsignup_extra_fieldslite/includes/Modules/Recaptcha.php:54
filterregistration_errorslite/includes/Modules/Recaptcha.php:57
actionlostpassword_postlite/includes/Modules/Recaptcha.php:58
filterauthenticatelite/includes/Modules/Recaptcha.php:59
actionadmin_enqueue_scriptslite/includes/Plugin.php:128
actionadmin_enqueue_scriptslite/includes/Plugin.php:129
actionadmin_menulite/includes/Plugin.php:131
actionadmin_print_scriptslite/includes/Plugin.php:133
actionadmin_initlite/includes/Plugin.php:134
actionadmin_initlite/includes/Plugin.php:135
actionadmin_noticeslite/includes/Plugin.php:136
actionadmin_noticeslite/includes/Plugin.php:137
filteradmin_footer_textlite/includes/Plugin.php:138
actionadmin_print_scriptslite/includes/Plugin.php:141
filtershow_admin_barlite/includes/Plugin.php:143
filterautomatic_updater_disabledlite/includes/Plugin.php:146
actionin_plugin_update_message-utilitify/utilitify.phplite/includes/Plugin.php:149
actionwp_enqueue_scriptslite/includes/Plugin.php:165
actionwp_enqueue_scriptslite/includes/Plugin.php:166
actioninitlite/includes/Plugin.php:169
actionadmin_initlite/includes/Settings.php:97
actionadmin_noticeslite/includes/Settings.php:102
actionadmin_enqueue_scriptslite/includes/Settings.php:104
filterplugin_iconutilitify.php:90
actionadmin_noticesutilitify.php:120
actionplugins_loadedutilitify.php:177
Maintenance & Trust

Utilitify – Supercharge Your WordPress Site With Powerpack WordPress Utilities Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 1, 2025
PHP min version5.6.4
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Utilitify – Supercharge Your WordPress Site With Powerpack WordPress Utilities Developer Profile

KaizenCoders

15 plugins · 31K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
153 days
View full developer profile
Detection Fingerprints

How We Detect Utilitify – Supercharge Your WordPress Site With Powerpack WordPress Utilities

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/utilitify/lite/dist/styles/app.css/wp-content/plugins/utilitify/lite/dist/styles/utilitify-admin.css/wp-content/plugins/utilitify/lite/dist/styles/utilitify.css/wp-content/plugins/utilitify/lite/dist/scripts/app.js/wp-content/plugins/utilitify/lite/dist/scripts/utilitify-admin.js
Script Paths
/wp-content/plugins/utilitify/lite/dist/scripts/app.js/wp-content/plugins/utilitify/lite/dist/scripts/utilitify-admin.js
Version Parameters
utilitify/1.1.1

HTML / DOM Fingerprints

CSS Classes
utilitify-admin
Data Attributes
data-utilitify-settings
JS Globals
utilitify_settings
REST Endpoints
/wp-json/utilitify/v1/get_data
FAQ

Frequently Asked Questions about Utilitify – Supercharge Your WordPress Site With Powerpack WordPress Utilities