B2App – Android & iOS native apps builder without using code Security & Risk Analysis

wordpress.org/plugins/b2app-no-code-mobile-app-builder

This Plugin is used for convert WooCommerce store to Android & iOS mobile app without using code.

10 active installs v1.0.0 PHP 5.6+ WP 4.5.0+ Updated Mar 22, 2022
convert-woocommerce-to-mobile-appwoocommerce-app-builderwoocommerce-mobile-app-builderwoocommerce-to-android-appwoocommerce-to-mobile-app
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is B2App – Android & iOS native apps builder without using code Safe to Use in 2026?

Generally Safe

Score 85/100

B2App – Android & iOS native apps builder without using code has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The b2app-no-code-mobile-app-builder plugin version 1.0.0 exhibits a generally positive security posture based on the provided static analysis. The absence of any known vulnerabilities in its history is a strong indicator of mature development practices. Furthermore, the code analysis shows a commendable adherence to security best practices, with 100% of SQL queries using prepared statements and all identified outputs being properly escaped. The plugin also avoids bundled libraries, which can sometimes introduce vulnerabilities if not kept up-to-date.

However, there are several areas that warrant attention and introduce potential risks. The most significant concern stems from the taint analysis, which identified two flows with unsanitized paths. While no critical or high severity issues were reported, unsanitized paths can be a precursor to path traversal or other file system vulnerabilities. Additionally, the complete lack of nonce checks and capability checks on any of the identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) is a critical oversight. This means that any user, regardless of their role or permissions, could potentially trigger actions within the plugin, creating a significant attack surface that is entirely unprotected.

In conclusion, while the plugin demonstrates strengths in data sanitization and SQL handling, the absence of crucial authorization and input validation mechanisms on its entry points presents a notable security weakness. The identified unsanitized paths, though not currently exploited, also require investigation. Developers should prioritize implementing robust nonce and capability checks to mitigate these risks and ensure that the plugin's functionalities are only accessible to authorized users.

Key Concerns

  • Unsanitized paths in taint analysis
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

B2App – Android & iOS native apps builder without using code Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

B2App – Android & iOS native apps builder without using code Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
50 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
4
Bundled Libraries
0

Output Escaping

100% escaped50 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
save (admin\class-b2app-app-builder-wc-settings.php:112)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

B2App – Android & iOS native apps builder without using code Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
filterwoocommerce_settings_tabs_arrayadmin\class-b2app-app-builder-wc-settings.php:34
actionadmin_noticesadmin\class-b2app-app-builder-wc-settings.php:260
actionadmin_noticesadmin\class-b2app-app-builder-wc-settings.php:264
actionadmin_noticesadmin\class-b2app-app-builder-wc-settings.php:270
actionadmin_noticesb2app-app-builder.php:51
actionplugins_loadedb2app-app-builder.php:105
actionplugins_loadedincludes\class-b2app-app-builder.php:142
actionadmin_enqueue_scriptsincludes\class-b2app-app-builder.php:157
actionadmin_enqueue_scriptsincludes\class-b2app-app-builder.php:158
filterwoocommerce_get_settings_pagesincludes\class-b2app-app-builder.php:161
actionwp_enqueue_scriptsincludes\class-b2app-app-builder.php:177
actionwp_enqueue_scriptsincludes\class-b2app-app-builder.php:178
Maintenance & Trust

B2App – Android & iOS native apps builder without using code Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedMar 22, 2022
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

B2App – Android & iOS native apps builder without using code Developer Profile

accessible892

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect B2App – Android & iOS native apps builder without using code

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/b2app-no-code-mobile-app-builder/admin/css/b2app-app-builder-admin.css/wp-content/plugins/b2app-no-code-mobile-app-builder/admin/js/b2app-app-builder-admin.js
Script Paths
/wp-content/plugins/b2app-no-code-mobile-app-builder/admin/js/b2app-app-builder-admin.js
Version Parameters
b2app-app-builder-admin.css?ver=b2app-app-builder-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
notice-errorwoocommerce
HTML Comments
<!-- B2App - Android & iOS native apps builder without using code for online store based on Woocommerce. It will allow you to create a beautiful and multifunctional mobile application in a few clicks. -->
JS Globals
b2app_admin_params
FAQ

Frequently Asked Questions about B2App – Android & iOS native apps builder without using code