
AppStore Lookup for WordPress Security & Risk Analysis
wordpress.org/plugins/appstore-lookupAdds shortcodes that display data from iOS and Mac AppStore applications.
Is AppStore Lookup for WordPress Safe to Use in 2026?
Generally Safe
Score 85/100AppStore Lookup for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "appstore-lookup" v1.5.1 plugin exhibits a generally good security posture with respect to its attack surface, showing no AJAX handlers, REST API routes, shortcodes, or cron events. This significantly limits the plugin's exposure to direct external manipulation. Furthermore, all identified SQL queries utilize prepared statements, indicating a strong defense against SQL injection vulnerabilities. The absence of known CVEs and past vulnerabilities is also a positive sign of a well-maintained codebase.
However, significant concerns arise from the static code analysis. The most alarming finding is that 100% of the 8 identified output operations are not properly escaped. This leaves the plugin highly susceptible to Cross-Site Scripting (XSS) attacks, where malicious scripts could be injected and executed within a user's browser. Additionally, the taint analysis revealed one flow with an unsanitized path, which, while not classified as critical or high, still represents a potential risk for path traversal or similar vulnerabilities if not handled carefully.
Despite the lack of historical vulnerabilities, the identified code signals for unescaped output and unsanitized paths warrant attention. The absence of nonce checks and capability checks on any potential entry points, though the attack surface is zero, implies that if any entry points were to be introduced in future versions without proper checks, the risks would be amplified. In conclusion, while the plugin has a minimal attack surface and good SQL practices, the prevalent lack of output escaping and the presence of an unsanitized path represent critical security weaknesses that need immediate remediation.
Key Concerns
- 0% output escaping
- Unsanitized path in taint flow
- No nonce checks
- No capability checks
AppStore Lookup for WordPress Security Vulnerabilities
AppStore Lookup for WordPress Code Analysis
Output Escaping
Data Flow Analysis
AppStore Lookup for WordPress Attack Surface
WordPress Hooks 2
Maintenance & Trust
AppStore Lookup for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
AppStore Lookup for WordPress Alternatives
App Reviews LITE
app-reviews-lite
Carousel to display iOS app ratings & reviews right from the App Store in real time on your Wordpress site. No maintenance required.
AppStore Links
appstore
Plugin for easy linking to (Mac) AppStore Apps. You can use the PGH-ID for automatically creating Affiliate-Links
TheBbApp: Native Mobile App Template for WordPress
thebbapp
BbApp is a native mobile application with push alerts, instant loading and offline mode for WordPress. Also works with BBPress.
Multi Device Switcher
multi-device-switcher
Multi Device Switcher plugin allows you to set a separate theme for device (Smart Phone, Tablet PC, Mobile Phone, Game and custom).
Retina @2x
retina-2x
A plugin that looks for retina images automatically based on the @2x naming convention.
AppStore Lookup for WordPress Developer Profile
1 plugin · 10 total installs
How We Detect AppStore Lookup for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/appstore-lookup/css/asl.css/wp-content/plugins/appstore-lookup/js/appstore-lookup.js/wp-content/plugins/appstore-lookup/js/appstore-lookup.jsappstore-lookup/style.css?ver=appstore-lookup/appstore-lookup.js?ver=HTML / DOM Fingerprints
asl-linkasl-link-imgasl-icon-imgasl-screenshot-listasl-app-screenshotdata-id<a href=<img src=<ul class="asl-screenshot-list"><li class="asl-app-screenshot">