
B2App – Android & iOS native apps builder without using code Security & Risk Analysis
wordpress.org/plugins/b2app-no-code-mobile-app-builderThis Plugin is used for convert WooCommerce store to Android & iOS mobile app without using code.
Is B2App – Android & iOS native apps builder without using code Safe to Use in 2026?
Generally Safe
Score 85/100B2App – Android & iOS native apps builder without using code has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The b2app-no-code-mobile-app-builder plugin version 1.0.0 exhibits a generally positive security posture based on the provided static analysis. The absence of any known vulnerabilities in its history is a strong indicator of mature development practices. Furthermore, the code analysis shows a commendable adherence to security best practices, with 100% of SQL queries using prepared statements and all identified outputs being properly escaped. The plugin also avoids bundled libraries, which can sometimes introduce vulnerabilities if not kept up-to-date.
However, there are several areas that warrant attention and introduce potential risks. The most significant concern stems from the taint analysis, which identified two flows with unsanitized paths. While no critical or high severity issues were reported, unsanitized paths can be a precursor to path traversal or other file system vulnerabilities. Additionally, the complete lack of nonce checks and capability checks on any of the identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) is a critical oversight. This means that any user, regardless of their role or permissions, could potentially trigger actions within the plugin, creating a significant attack surface that is entirely unprotected.
In conclusion, while the plugin demonstrates strengths in data sanitization and SQL handling, the absence of crucial authorization and input validation mechanisms on its entry points presents a notable security weakness. The identified unsanitized paths, though not currently exploited, also require investigation. Developers should prioritize implementing robust nonce and capability checks to mitigate these risks and ensure that the plugin's functionalities are only accessible to authorized users.
Key Concerns
- Unsanitized paths in taint analysis
- No nonce checks on entry points
- No capability checks on entry points
B2App – Android & iOS native apps builder without using code Security Vulnerabilities
B2App – Android & iOS native apps builder without using code Code Analysis
Output Escaping
Data Flow Analysis
B2App – Android & iOS native apps builder without using code Attack Surface
WordPress Hooks 12
Maintenance & Trust
B2App – Android & iOS native apps builder without using code Maintenance & Trust
Maintenance Signals
Community Trust
B2App – Android & iOS native apps builder without using code Alternatives
B2App – Android & iOS native apps builder without using code Developer Profile
1 plugin · 10 total installs
How We Detect B2App – Android & iOS native apps builder without using code
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/b2app-no-code-mobile-app-builder/admin/css/b2app-app-builder-admin.css/wp-content/plugins/b2app-no-code-mobile-app-builder/admin/js/b2app-app-builder-admin.js/wp-content/plugins/b2app-no-code-mobile-app-builder/admin/js/b2app-app-builder-admin.jsb2app-app-builder-admin.css?ver=b2app-app-builder-admin.js?ver=HTML / DOM Fingerprints
notice-errorwoocommerce<!-- B2App - Android & iOS native apps builder without using code for online store based on Woocommerce. It will allow you to create a beautiful and multifunctional mobile application in a few clicks. -->b2app_admin_params