
AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker) Security & Risk Analysis
wordpress.org/plugins/appmysiteTurn your WordPress or WooCommerce site into a native Android & iOS app in minutes — no coding required.
Is AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker) Safe to Use in 2026?
Mostly Safe
Score 77/100AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker) is generally safe to use. 2 past CVEs were resolved. Keep it updated.
The 'appmysite' plugin v3.15.2 presents a mixed security posture. While it demonstrates strengths such as the absence of dangerous functions and the use of prepared statements for all SQL queries, significant concerns arise from its attack surface. Specifically, two AJAX handlers lack authentication checks, creating potential entry points for unauthorized actions. The plugin also exhibits a history of medium severity vulnerabilities, including missing authorization and exposure of sensitive information, with one such vulnerability remaining unpatched as of September 2025. This pattern suggests recurring security weaknesses that require attention. Although Taint analysis shows no critical or high severity flows, and a good percentage of output is escaped, the unauthenticated AJAX endpoints combined with past authorization issues indicate a notable risk that needs to be addressed.
Key Concerns
- Unprotected AJAX handlers
- Unpatched medium severity CVE
- History of missing authorization vulnerabilities
- Output escaping is less than ideal (58%)
AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker) Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
AppMySite <= 3.14.0 - Missing Authorization
AppMySite <= 3.11.0 - Unauthenticated Information Disclsoure
AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker) Code Analysis
Output Escaping
AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker) Attack Surface
AJAX Handlers 3
REST API Routes 29
WordPress Hooks 30
Maintenance & Trust
AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker) Maintenance & Trust
Maintenance Signals
Community Trust
AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker) Alternatives
Mobile App Editor – WordPress to Android App Builder
mobile-app-editor
Native Android App Builder for wordpress and woocommerce.
B2App – Android & iOS native apps builder without using code
b2app-no-code-mobile-app-builder
This Plugin is used for convert WooCommerce store to Android & iOS mobile app without using code.
AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker) Developer Profile
1 plugin · 8K total installs
How We Detect AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/appmysite/assets/js/ams-plugin-deactivation-survey.js/wp-content/plugins/appmysite/assets/css/ams-plugin-deactivation-survey.css/wp-content/plugins/appmysite/assets/js/ams-main.js/wp-content/plugins/appmysite/assets/css/ams-main.css/wp-content/plugins/appmysite/assets/js/ams-plugin-deactivation-survey.js/wp-content/plugins/appmysite/assets/js/ams-main.jsappmysite/style.css?ver=appmysite/script.js?ver=HTML / DOM Fingerprints
ams-plugin-deactivation-survey-formams-deactivation-containerAppMySitedata-ams-noncefrontend_ajax_object/wp-json/appmysite/v1/config