Appza – No-Code Mobile App Builder for WordPress Security & Risk Analysis

wordpress.org/plugins/appza-builder

Turn your WordPress site into a native iOS & Android mobile app – right from your dashboard. No coding. No external platforms.

10 active installs v2.1.1 PHP 7.4+ WP 6.2+ Updated Mar 15, 2026
app-builderwoocommerce-appfluent-community-appmobile-app-builderno-code-app
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Appza – No-Code Mobile App Builder for WordPress Safe to Use in 2026?

Generally Safe

Score 100/100

Appza – No-Code Mobile App Builder for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The plugin "appza-builder" v2.1.1 exhibits a generally strong security posture, with no known vulnerabilities or CVEs recorded. The static analysis reveals excellent practices in output escaping, with 100% of outputs being properly escaped, and a high percentage (96%) of SQL queries utilizing prepared statements, which significantly mitigates the risk of SQL injection. The absence of any identified taint flows with unsanitized paths further reinforces this. However, the presence of a "dangerous function" signal, specifically `set_time_limit`, warrants attention. While not inherently a vulnerability, this function can be misused to prolong script execution, potentially leading to Denial of Service (DoS) if exploited, especially if its usage is not carefully controlled or validated.

The limited attack surface identified, with zero unprotected entry points across AJAX handlers, REST API routes, shortcodes, and cron events, is a significant positive. This suggests that the plugin's core functionality is well-protected from unauthorized access. The inclusion of a nonce check and a capability check, although only one each, indicates an awareness of basic WordPress security mechanisms. The lack of bundled libraries is also a benefit, as it avoids the risk of carrying outdated or vulnerable third-party code. Overall, while the plugin demonstrates good security practices and a clean vulnerability history, the `set_time_limit` function represents a potential area for scrutiny and should be reviewed for its implementation and context within the plugin to ensure it doesn't introduce unintended risks.

Key Concerns

  • Presence of dangerous function set_time_limit
Vulnerabilities
None known

Appza – No-Code Mobile App Builder for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Appza – No-Code Mobile App Builder for WordPress Release Timeline

v2.1.1Current
v2.1.0
v2.0
v1.1.4
v1.1.3
v1.0.3
Code Analysis
Analyzed Apr 16, 2026

Appza – No-Code Mobile App Builder for WordPress Code Analysis

Dangerous Functions
1
Raw SQL Queries
5
114 prepared
Unescaped Output
0
91 escaped
Nonce Checks
1
Capability Checks
1
File Operations
4
External Requests
9
Bundled Libraries
0

Dangerous Functions Found

set_time_limitset_time_limit(600);src/Helper/Appza_Helper_Theme_Activator.php:100

SQL Query Safety

96% prepared119 total queries

Output Escaping

100% escaped91 total outputs
Attack Surface

Appza – No-Code Mobile App Builder for WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionadmin_enqueue_scriptsincludes/class-mobile-store-builder.php:158
actionadmin_enqueue_scriptsincludes/class-mobile-store-builder.php:159
actionadmin_menuincludes/class-mobile-store-builder.php:160
actionrest_api_initincludes/class-mobile-store-builder.php:161
actionadmin_initincludes/class-mobile-store-builder.php:162
actionadmin_noticesincludes/class-mobile-store-builder.php:163
actionwp_enqueue_scriptsincludes/class-mobile-store-builder.php:178
actionwp_enqueue_scriptsincludes/class-mobile-store-builder.php:179
actionrest_api_initincludes/class-mobile-store-builder.php:180
filterfluent_community/course_api_responseincludes/class-mobile-store-builder.php:182
filterfluent_community/course_lesson_api_responseincludes/class-mobile-store-builder.php:183
filterwp_is_application_passwords_availablemobile-store-builder.php:92
filterwp_is_application_passwords_supportedmobile-store-builder.php:93
filterfluent_community/can_view_comments_course_lessonsrc/Supports/FCommunity/Appza_FCOM_Mobile_Course.php:895
filterfluent_community/last_activity_date_for_unread_feedssrc/Supports/FCommunity/Appza_FCOM_Mobile_Space.php:599
filtertutor_course_contents_post_typessrc/Supports/Tutor/Appza_Tutor_Course.php:368
Maintenance & Trust

Appza – No-Code Mobile App Builder for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 15, 2026
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Appza – No-Code Mobile App Builder for WordPress Developer Profile

Noor Khan

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Appza – No-Code Mobile App Builder for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/appza-builder/admin/frontend/build/index.css/wp-content/plugins/appza-builder/admin/js/appza-builder-admin-deactivate-confirmation.js/wp-content/plugins/appza-builder/admin/frontend/build/index.js
Script Paths
/wp-content/plugins/appza-builder/admin/frontend/build/index.js/wp-content/plugins/appza-builder/admin/js/appza-builder-admin-deactivate-confirmation.js
Version Parameters
appza-builder/admin/frontend/build/index.css?ver=appza-builder/admin/js/appza-builder-admin-deactivate-confirmation.js?ver=appza-builder/admin/frontend/build/index.js?ver=

HTML / DOM Fingerprints

CSS Classes
appza-builder-admin-deactivate-confirmation
JS Globals
appLocalizer
FAQ

Frequently Asked Questions about Appza – No-Code Mobile App Builder for WordPress