
Add to Home Screen & Progressive Web App Security & Risk Analysis
wordpress.org/plugins/add-to-home-screen-wpTurn your WordPress site into a Web App (PWA) with a stylish 'Add to Home Screen' prompt for iOS & Android. Boost engagement without native app costs!
Is Add to Home Screen & Progressive Web App Safe to Use in 2026?
Generally Safe
Score 100/100Add to Home Screen & Progressive Web App has a strong security track record. Known vulnerabilities have been patched promptly.
The 'add-to-home-screen-wp' plugin v2.7.4 demonstrates a generally good security posture, with a notable absence of critical or high-severity code signals. The analysis indicates strong adherence to secure coding practices, including 100% of SQL queries using prepared statements and a high percentage (90%) of output properly escaped. The limited attack surface, with only two AJAX handlers and no exposed REST API routes or shortcodes, further contributes to a reduced risk profile. The presence of nonce and capability checks on the identified entry points is a positive indicator of basic security controls.
However, the plugin is not without potential concerns. The vulnerability history, despite having no currently unpatched CVEs, reveals a past medium-severity Cross-Site Scripting (XSS) vulnerability. While this specific vulnerability is patched, the past occurrence of XSS suggests that input sanitization might be an area that requires continued vigilance. The static analysis also shows that while most outputs are escaped, there's a small percentage that is not, which could theoretically be exploited if combined with specific unsanitized inputs, though no taint flows indicated this during analysis.
In conclusion, the plugin exhibits a commendable level of security awareness and implementation. The strengths lie in its robust SQL handling, extensive output escaping, and well-controlled attack surface. The primary weakness identified is the past XSS vulnerability, which, although resolved, warrants ongoing attention to ensure input validation remains comprehensive. The plugin's current version appears to be in a stable and relatively secure state.
Key Concerns
- Past medium XSS vulnerability
- 10% of outputs not properly escaped
Add to Home Screen & Progressive Web App Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Add to home screen WP Plugin <= 2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Add to Home Screen & Progressive Web App Code Analysis
Output Escaping
Data Flow Analysis
Add to Home Screen & Progressive Web App Attack Surface
AJAX Handlers 2
WordPress Hooks 10
Maintenance & Trust
Add to Home Screen & Progressive Web App Maintenance & Trust
Maintenance Signals
Community Trust
Add to Home Screen & Progressive Web App Alternatives
Hyper PWA
hyper-pwa
Provide Manifest and Service Worker, convert WordPress into Progressive Web Apps (PWA).
PWA for WordPress
pwa4wp
PWA for WordPress makes your WordPress site to PWA (Progressive Web App) and makes control of PWA data caches easy.
WP-AppKit – Mobile apps and PWA for WordPress
wp-appkit
Important ✋: beginning with version 1.5.3, we don't support anymore native iOS app. This is a tough choice we explain here.
Progressify – All-in-One Progressive Web App (PWA) on Autopilot
progressify
Turn your site into an app-like PWA with install prompts, offline use, push notifications, and more to boost engagement, repeat visits, and sales.
SORTD
sortd
Introducing The Most Advanced and Intuitive WordPress plug-in to build Progressive Web Apps & Accelerated Mobile Pages for content websites.
Add to Home Screen & Progressive Web App Developer Profile
4 plugins · 1K total installs
How We Detect Add to Home Screen & Progressive Web App
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/add-to-home-screen-wp/assets/css/app.css/wp-content/plugins/add-to-home-screen-wp/assets/js/app.js/wp-content/plugins/add-to-home-screen-wp/assets/js/manifest.js/wp-content/plugins/add-to-home-screen-wp/assets/js/pwabuilder-sw.js/wp-content/plugins/add-to-home-screen-wp/assets/js/app.js/wp-content/plugins/add-to-home-screen-wp/assets/js/manifest.js/wp-content/plugins/add-to-home-screen-wp/assets/js/pwabuilder-sw.jsadd-to-home-screen-wp/assets/css/app.css?ver=add-to-home-screen-wp/assets/js/app.js?ver=add-to-home-screen-wp/assets/js/manifest.js?ver=add-to-home-screen-wp/assets/js/pwabuilder-sw.js?ver=HTML / DOM Fingerprints
athswp_custom_iconathswp_containerathswp_message_wrapper<!-- ATHSWP --><!-- SimpleATHSOptions class loaded -->data-athswp-starturldata-athswp-touchicondata-athswp-lifespandata-athswp-startdelaydata-athswp-bottomoffsetdata-athswp-animationin+8 moreathswp_options