Add To Home Screen on iOS and PWA Security & Risk Analysis

wordpress.org/plugins/add-to-home-screen-on-ios-pwa

Add to Home Screen for iOS – PWA Support with Custom Icons and Popup

0 active installs v1.0.0 PHP 7.0+ WP 5.6+ Updated Jan 16, 2026
iosmobilepopuppwaweb-app
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Add To Home Screen on iOS and PWA Safe to Use in 2026?

Generally Safe

Score 100/100

Add To Home Screen on iOS and PWA has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "add-to-home-screen-on-ios-pwa" plugin v1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by not utilizing dangerous functions, performing all SQL queries using prepared statements, and having a high percentage of properly escaped outputs. The absence of file operations and external HTTP requests is also reassuring. Furthermore, the plugin has no known vulnerabilities (CVEs) and a clean vulnerability history, suggesting a generally well-maintained codebase.

However, significant concerns arise from the static analysis. The plugin exposes a total of four entry points, three of which are AJAX handlers that lack authentication checks. This creates a substantial attack surface that is unprotected, potentially allowing unauthenticated users to trigger actions or manipulate plugin behavior. While the taint analysis did not reveal any immediate critical or high severity issues, the presence of unprotected AJAX handlers makes it easier for attackers to exploit potential logic flaws that might not be immediately apparent in taint analysis alone.

In conclusion, while the plugin benefits from secure coding practices in areas like SQL and output handling, and has a history of no known vulnerabilities, the critical weakness lies in its unprotected AJAX endpoints. This significantly elevates the risk profile, making it vulnerable to various attacks if not properly secured or if future updates introduce vulnerabilities to these exposed endpoints. The plugin's strengths in other areas are overshadowed by this significant security oversight.

Key Concerns

  • Unprotected AJAX handlers
  • Large attack surface without auth
Vulnerabilities
None known

Add To Home Screen on iOS and PWA Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Add To Home Screen on iOS and PWA Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
52
795 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped847 total outputs
Attack Surface
3 unprotected

Add To Home Screen on iOS and PWA Attack Surface

Entry Points4
Unprotected3

AJAX Handlers 3

authwp_ajax_addtohos_admin_actionincludes\class-addtohos.php:189
authwp_ajax_addtohos_public_actionincludes\class-addtohos.php:212
noprivwp_ajax_addtohos_public_actionincludes\class-addtohos.php:218

Shortcodes 1

[addtohos_ios_add_to_home_screen_button] shortcodes\shortcode-addtohos.php:13
WordPress Hooks 17
actioninitactions.php:14
actionwp_footeractions.php:18
filterplugin_action_links_add-to-home-screen-on-ios-pwa/add-to-home-screen-on-ios-pwa.phpactions.php:24
actionwp_enqueue_scriptselementor-elements\elementor-init.php:221
actionwp_enqueue_scriptselementor-elements\elementor-init.php:222
actionelementor/elements/categories_registeredelementor-elements\elementor-init.php:224
actionelementor/widgets/registerelementor-elements\elementor-init.php:225
actionelementor/initelementor-elements\elementor-init.php:236
actionwp_headinc\addtohos-configurator.php:27
actionwp_enqueue_scriptsinc\addtohos-configurator.php:28
actionadmin_enqueue_scriptsincludes\class-addtohos.php:177
actionadmin_enqueue_scriptsincludes\class-addtohos.php:178
actionadmin_menuincludes\class-addtohos.php:183
actionwp_enqueue_scriptsincludes\class-addtohos.php:208
actionwp_enqueue_scriptsincludes\class-addtohos.php:209
actionplugins_loadedincludes\class-addtohos.php:269
filterajax_query_attachments_argsincludes\class-addtohos.php:309
Maintenance & Trust

Add To Home Screen on iOS and PWA Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 16, 2026
PHP min version7.0
Downloads157

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Add To Home Screen on iOS and PWA Developer Profile

WPDirectoryKit

6 plugins · 4K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
101 days
View full developer profile
Detection Fingerprints

How We Detect Add To Home Screen on iOS and PWA

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/add-to-home-screen-on-ios-pwa/public/js/spectrum-colorpicker2/spectrum.css/wp-content/plugins/add-to-home-screen-on-ios-pwa/public/css/jquery-ui.css/wp-content/plugins/add-to-home-screen-on-ios-pwa/css/addtohos-admin.css/wp-content/plugins/add-to-home-screen-on-ios-pwa/css/addtohos-admin-responsive.css/wp-content/plugins/add-to-home-screen-on-ios-pwa/public/js/spectrum-colorpicker2/spectrum.js/wp-content/plugins/add-to-home-screen-on-ios-pwa/admin/js/addtohos-admin.js/wp-content/plugins/add-to-home-screen-on-ios-pwa/admin/js/addtohos-plugin-installer.js
Script Paths
/wp-content/plugins/add-to-home-screen-on-ios-pwa/public/js/spectrum-colorpicker2/spectrum.js/wp-content/plugins/add-to-home-screen-on-ios-pwa/admin/js/addtohos-admin.js/wp-content/plugins/add-to-home-screen-on-ios-pwa/admin/js/addtohos-plugin-installer.js
Version Parameters
add-to-home-screen-on-ios-pwa/css/addtohos-admin.css?ver=add-to-home-screen-on-ios-pwa/css/addtohos-admin-responsive.css?ver=add-to-home-screen-on-ios-pwa/admin/js/addtohos-admin.js?ver=add-to-home-screen-on-ios-pwa/admin/js/addtohos-plugin-installer.js?ver=

HTML / DOM Fingerprints

CSS Classes
addtohos-admin-settings
HTML Comments
<!-- Generated by Add To Home Screen on iOS and PWA -->
Data Attributes
data-addtohos-nonce
JS Globals
addtohos_script_parametersaddtohos_importer_params
FAQ

Frequently Asked Questions about Add To Home Screen on iOS and PWA