Apperr – Android and iOS App builder for WooCommerce and WordPress Security & Risk Analysis

wordpress.org/plugins/apperr

Get Android and iOS App for your WooCommerce store and WordPress Website in minutes

0 active installs v0.1.0 PHP + WP 3.0.1+ Updated Mar 1, 2022
android-appappnative-appwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Apperr – Android and iOS App builder for WooCommerce and WordPress Safe to Use in 2026?

Generally Safe

Score 85/100

Apperr – Android and iOS App builder for WooCommerce and WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "apperr" plugin v0.1.0 exhibits a concerning security posture due to a high number of unprotected entry points. With 7 out of 8 identified entry points lacking authentication checks, the plugin is highly susceptible to unauthorized access and execution of potentially malicious actions. While the plugin demonstrates good practices in its use of prepared statements for SQL queries and has no recorded vulnerability history, the significant number of unprotected AJAX handlers presents a critical risk. The taint analysis, although showing no critical or high severity unsanitized flows, is limited by the small number of flows analyzed, and the presence of unsanitized paths is a red flag requiring further investigation.

The plugin's strengths lie in its avoidance of dangerous functions, secure SQL handling, and a clean vulnerability history. However, these positives are heavily outweighed by the critical weakness of unprotected AJAX endpoints. The lack of nonce checks on these handlers further exacerbates the risk, making cross-site request forgery (CSRF) attacks highly feasible. The low percentage of properly escaped output is also a concern, potentially leading to cross-site scripting (XSS) vulnerabilities.

Key Concerns

  • 7 unprotected AJAX handlers
  • 3 flows with unsanitized paths
  • 0 nonce checks
  • 17% of outputs properly escaped
  • Bundled Freemius v1.0 library
Vulnerabilities
None known

Apperr – Android and iOS App builder for WooCommerce and WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Apperr – Android and iOS App builder for WooCommerce and WordPress Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Apperr – Android and iOS App builder for WooCommerce and WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
1 escaped
Nonce Checks
0
Capability Checks
3
File Operations
3
External Requests
1
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

17% escaped6 total outputs
Data Flows · Security
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
submit_build (includes/Admin/AjaxHook.php:84)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
7 unprotected

Apperr – Android and iOS App builder for WooCommerce and WordPress Attack Surface

Entry Points8
Unprotected7

AJAX Handlers 7

authwp_ajax_post_dataincludes/Admin/AjaxHook.php:7
authwp_ajax_save_optionsincludes/Admin/AjaxHook.php:8
authwp_ajax_get_optionsincludes/Admin/AjaxHook.php:9
authwp_ajax_get_menusincludes/Admin/AjaxHook.php:10
authwp_ajax_get_taxonomiesincludes/Admin/AjaxHook.php:11
authwp_ajax_submit_buildincludes/Admin/AjaxHook.php:12
authwp_ajax_install_jwt_auth_plginincludes/Admin/AjaxHook.php:13

Shortcodes 1

[apperr] includes/Frontend.php:10
WordPress Hooks 10
actionplugins_loadedapperr.php:108
actioninitapperr.php:240
actioninitapperr.php:242
actionadmin_enqueue_scriptsincludes/Actions.php:18
actionrest_api_initincludes/Actions.php:19
actionadmin_menuincludes/Admin.php:10
actionadmin_enqueue_scriptsincludes/Admin.php:41
actionrest_api_initincludes/Api.php:17
actionadmin_enqueue_scriptsincludes/Assets.php:12
actionwp_enqueue_scriptsincludes/Assets.php:14
Maintenance & Trust

Apperr – Android and iOS App builder for WooCommerce and WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedMar 1, 2022
PHP min version
Downloads961

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Apperr – Android and iOS App builder for WooCommerce and WordPress Developer Profile

prasadkirpekar

7 plugins · 91K total installs

71
trust score
Avg Security Score
89/100
Avg Patch Time
153 days
View full developer profile
Detection Fingerprints

How We Detect Apperr – Android and iOS App builder for WooCommerce and WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/apperr/assets/css/apperr.css/wp-content/plugins/apperr/assets/js/apperr.js
Script Paths
/wp-content/plugins/apperr/assets/js/apperr.js
Version Parameters
apperr/assets/css/apperr.css?ver=apperr/assets/js/apperr.js?ver=

HTML / DOM Fingerprints

CSS Classes
apperr-settings-wrap
Data Attributes
data-apperr-target
JS Globals
apperr_params
FAQ

Frequently Asked Questions about Apperr – Android and iOS App builder for WooCommerce and WordPress