CodeQuill Web to App Security & Risk Analysis

wordpress.org/plugins/codequill-web-to-app

Convert your WordPress site into a Progressive Web App (PWA). Add an Install App button and manage settings directly from the dashboard.

0 active installs v1.0.5 PHP 8.0+ WP 6.0+ Updated Mar 12, 2026
install-appmobile-appprogressive-web-apppwaweb-to-app
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CodeQuill Web to App Safe to Use in 2026?

Generally Safe

Score 100/100

CodeQuill Web to App has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 23d ago
Risk Assessment

The code analysis for codequill-web-to-app version 1.0.5 indicates a generally strong security posture. The plugin boasts zero entry points like AJAX handlers, REST API routes, shortcodes, and cron events that are unprotected, which is excellent. All identified SQL queries utilize prepared statements, a critical best practice to prevent SQL injection. Capability checks are present, further limiting unauthorized access to certain functionalities. The absence of external HTTP requests also reduces the risk of client-side attacks.

However, there are a few areas for improvement. With 52 total outputs, only 65% are properly escaped, leaving a notable portion potentially vulnerable to cross-site scripting (XSS) attacks. The lack of nonce checks, particularly if there were any hidden entry points or AJAX calls not detected, could also present a risk. The analysis also shows two file operations, and without further inspection, it's difficult to assess their security. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive sign of the developers' diligence or the plugin's early stage.

In conclusion, while the plugin exhibits many good security practices, the unescaped output is the most significant concern identified in the static analysis. The clean vulnerability history is reassuring, but it doesn't negate the potential risks present in the current code. Addressing the output escaping issues should be a priority to further harden the plugin's security.

Key Concerns

  • 35% of outputs are not properly escaped
  • No nonce checks implemented
Vulnerabilities
None known

CodeQuill Web to App Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

CodeQuill Web to App Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
18
34 escaped
Nonce Checks
0
Capability Checks
2
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

65% escaped52 total outputs
Attack Surface

CodeQuill Web to App Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionadmin_menu1.0.5\admin\admin.php:7
actionadmin_init1.0.5\admin\admin.php:8
actionadmin_enqueue_scripts1.0.5\admin\admin.php:11
actionplugins_loaded1.0.5\codequill-web-to-app.php:31
actionwp_head1.0.5\function\function.php:8
actionwp_footer1.0.5\function\function.php:9
actionwp_enqueue_scripts1.0.5\function\function.php:10
actioninit1.0.5\function\function.php:13
actionadmin_menuadmin\admin.php:7
actionadmin_initadmin\admin.php:8
actionadmin_enqueue_scriptsadmin\admin.php:11
actionplugins_loadedcodequill-web-to-app.php:31
actionwp_headfunction\function.php:8
actionwp_footerfunction\function.php:9
actionwp_enqueue_scriptsfunction\function.php:10
actioninitfunction\function.php:13
Maintenance & Trust

CodeQuill Web to App Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 12, 2026
PHP min version8.0
Downloads168

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

CodeQuill Web to App Developer Profile

WPcodeQuill

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CodeQuill Web to App

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/codequill-web-to-app/assets/css/admin.css
Version Parameters
codequill-web-to-app/assets/css/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
codequill-pwa-wrapcodequill-pwa-cardcodequill-pwa-headercodequill-pwa-footercodequill-promo-wrapcodequill-promo-gridcodequill-promo-itemcodequill-promo-img+4 more
FAQ

Frequently Asked Questions about CodeQuill Web to App