
App Store Assistant Security & Risk Analysis
wordpress.org/plugins/app-store-assistantLets you display the detail of an item or an RSS feed from Apple's App Store, iTunes Stores or Amazon.com. Affiliate ready.
Is App Store Assistant Safe to Use in 2026?
Generally Safe
Score 85/100App Store Assistant has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "app-store-assistant" plugin v6.9.1 exhibits a mixed security posture. On the positive side, it has a clean vulnerability history with no known CVEs recorded, and all its SQL queries are secured using prepared statements, which is a strong indicator of good database interaction practices. The presence of nonce and capability checks, though limited, is also a positive sign. However, significant concerns arise from the static analysis.
The plugin has a total of 20 entry points, with 2 AJAX handlers lacking any authentication checks. This presents a direct and exploitable attack vector if these handlers perform sensitive operations or accept untrusted input. Furthermore, the taint analysis revealed 3 flows with unsanitized paths, which could potentially lead to vulnerabilities if these flows involve user-supplied data being used in file operations or other insecure contexts. The limited output escaping (7%) is also a significant concern, suggesting a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially given the large number of total outputs.
While the plugin's history is clean, this cannot overshadow the immediate risks identified in the current version's code. The lack of authorization on AJAX handlers and the presence of unsanitized paths are critical vulnerabilities that need immediate attention. The outdated bundled jQuery library also introduces a potential risk, as older versions are often susceptible to known exploits. The overall security posture is therefore compromised by these critical findings, despite the absence of historical vulnerabilities.
Key Concerns
- 2 AJAX handlers without auth checks
- 3 flows with unsanitized paths
- Low output escaping percentage (7%)
- Bundled outdated jQuery v1.10.2
App Store Assistant Security Vulnerabilities
App Store Assistant Release Timeline
App Store Assistant Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
App Store Assistant Attack Surface
AJAX Handlers 2
Shortcodes 18
WordPress Hooks 29
Maintenance & Trust
App Store Assistant Maintenance & Trust
Maintenance Signals
Community Trust
App Store Assistant Alternatives
AppStore Reviews Viewer
appstore-reviews-viewer
Adds a shortcode that displays reviews and ratings of an app from the iOS AppStore’s country you chose.
App Display Page
app-display-page
Adds a shortcode to display information about iOS apps from Apple's App Store.
WP App Store API
wp-app-store-landing-page
The WP App Store API allows you to search the App Store for any app information and use them to display on your site via shortcodes.
WP-Appbox
wp-appbox
With WP-Appbox you can add beautiful mobile app badges to your WordPress posts and pages simply by adding a shortcode.
GoodBarber
goodbarber
GoodBarber plugin allows you to retrieve WordPress content in order to create a native app for iOS and/or Android
App Store Assistant Developer Profile
1 plugin · 30 total installs
How We Detect App Store Assistant
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/app-store-assistant/css/app-store-assistant.css/wp-content/plugins/app-store-assistant/js/app-store-assistant.js/wp-content/plugins/app-store-assistant/js/tinymce/plugins/appstoreassistant/editor_plugin.jsApp Store Assistant v6.9.1/wp-content/plugins/app-store-assistant/js/app-store-assistant.js/wp-content/plugins/app-store-assistant/js/tinymce/plugins/appstoreassistant/editor_plugin.jsapp-store-assistant-css?ver=app-store-assistant-js?ver=HTML / DOM Fingerprints
asaWidget1data-app-idASA_PLUGIN_URLASA_PLUGIN_VERSIONASA_APPSTORE_URLCACHE_DIRECTORYCACHE_DIRECTORY_URL[asaf_atomfeed][asa_item][asa_list][asa_link]