
Add To Home Screen on iOS and PWA Security & Risk Analysis
wordpress.org/plugins/add-to-home-screen-on-ios-pwaAdd to Home Screen for iOS – PWA Support with Custom Icons and Popup
Is Add To Home Screen on iOS and PWA Safe to Use in 2026?
Generally Safe
Score 100/100Add To Home Screen on iOS and PWA has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "add-to-home-screen-on-ios-pwa" plugin v1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by not utilizing dangerous functions, performing all SQL queries using prepared statements, and having a high percentage of properly escaped outputs. The absence of file operations and external HTTP requests is also reassuring. Furthermore, the plugin has no known vulnerabilities (CVEs) and a clean vulnerability history, suggesting a generally well-maintained codebase.
However, significant concerns arise from the static analysis. The plugin exposes a total of four entry points, three of which are AJAX handlers that lack authentication checks. This creates a substantial attack surface that is unprotected, potentially allowing unauthenticated users to trigger actions or manipulate plugin behavior. While the taint analysis did not reveal any immediate critical or high severity issues, the presence of unprotected AJAX handlers makes it easier for attackers to exploit potential logic flaws that might not be immediately apparent in taint analysis alone.
In conclusion, while the plugin benefits from secure coding practices in areas like SQL and output handling, and has a history of no known vulnerabilities, the critical weakness lies in its unprotected AJAX endpoints. This significantly elevates the risk profile, making it vulnerable to various attacks if not properly secured or if future updates introduce vulnerabilities to these exposed endpoints. The plugin's strengths in other areas are overshadowed by this significant security oversight.
Key Concerns
- Unprotected AJAX handlers
- Large attack surface without auth
Add To Home Screen on iOS and PWA Security Vulnerabilities
Add To Home Screen on iOS and PWA Code Analysis
Output Escaping
Add To Home Screen on iOS and PWA Attack Surface
AJAX Handlers 3
Shortcodes 1
WordPress Hooks 17
Maintenance & Trust
Add To Home Screen on iOS and PWA Maintenance & Trust
Maintenance Signals
Community Trust
Add To Home Screen on iOS and PWA Alternatives
WP-AppKit – Mobile apps and PWA for WordPress
wp-appkit
Important ✋: beginning with version 1.5.3, we don't support anymore native iOS app. This is a tough choice we explain here.
miTT PWA FREE WP
mitt-pwa
miTT PWA FREE WP transforms your WordPress Website into a Progressive Web App (PWA) and makes it offline ready using Service Workers.
Add to Home Screen & Progressive Web App
add-to-home-screen-wp
Turn your WordPress site into a Web App (PWA) with a stylish 'Add to Home Screen' prompt for iOS & Android. Boost engagement without native app costs!
PWA for WordPress
pwa4wp
PWA for WordPress makes your WordPress site to PWA (Progressive Web App) and makes control of PWA data caches easy.
Progressify – All-in-One Progressive Web App (PWA) on Autopilot
progressify
Turn your site into an app-like PWA with install prompts, offline use, push notifications, and more to boost engagement, repeat visits, and sales.
Add To Home Screen on iOS and PWA Developer Profile
6 plugins · 4K total installs
How We Detect Add To Home Screen on iOS and PWA
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/add-to-home-screen-on-ios-pwa/public/js/spectrum-colorpicker2/spectrum.css/wp-content/plugins/add-to-home-screen-on-ios-pwa/public/css/jquery-ui.css/wp-content/plugins/add-to-home-screen-on-ios-pwa/css/addtohos-admin.css/wp-content/plugins/add-to-home-screen-on-ios-pwa/css/addtohos-admin-responsive.css/wp-content/plugins/add-to-home-screen-on-ios-pwa/public/js/spectrum-colorpicker2/spectrum.js/wp-content/plugins/add-to-home-screen-on-ios-pwa/admin/js/addtohos-admin.js/wp-content/plugins/add-to-home-screen-on-ios-pwa/admin/js/addtohos-plugin-installer.js/wp-content/plugins/add-to-home-screen-on-ios-pwa/public/js/spectrum-colorpicker2/spectrum.js/wp-content/plugins/add-to-home-screen-on-ios-pwa/admin/js/addtohos-admin.js/wp-content/plugins/add-to-home-screen-on-ios-pwa/admin/js/addtohos-plugin-installer.jsadd-to-home-screen-on-ios-pwa/css/addtohos-admin.css?ver=add-to-home-screen-on-ios-pwa/css/addtohos-admin-responsive.css?ver=add-to-home-screen-on-ios-pwa/admin/js/addtohos-admin.js?ver=add-to-home-screen-on-ios-pwa/admin/js/addtohos-plugin-installer.js?ver=HTML / DOM Fingerprints
addtohos-admin-settings<!-- Generated by Add To Home Screen on iOS and PWA -->data-addtohos-nonceaddtohos_script_parametersaddtohos_importer_params