
CodeQuill Web to App Security & Risk Analysis
wordpress.org/plugins/codequill-web-to-appConvert your WordPress site into a Progressive Web App (PWA). Add an Install App button and manage settings directly from the dashboard.
Is CodeQuill Web to App Safe to Use in 2026?
Generally Safe
Score 100/100CodeQuill Web to App has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The code analysis for codequill-web-to-app version 1.0.5 indicates a generally strong security posture. The plugin boasts zero entry points like AJAX handlers, REST API routes, shortcodes, and cron events that are unprotected, which is excellent. All identified SQL queries utilize prepared statements, a critical best practice to prevent SQL injection. Capability checks are present, further limiting unauthorized access to certain functionalities. The absence of external HTTP requests also reduces the risk of client-side attacks.
However, there are a few areas for improvement. With 52 total outputs, only 65% are properly escaped, leaving a notable portion potentially vulnerable to cross-site scripting (XSS) attacks. The lack of nonce checks, particularly if there were any hidden entry points or AJAX calls not detected, could also present a risk. The analysis also shows two file operations, and without further inspection, it's difficult to assess their security. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive sign of the developers' diligence or the plugin's early stage.
In conclusion, while the plugin exhibits many good security practices, the unescaped output is the most significant concern identified in the static analysis. The clean vulnerability history is reassuring, but it doesn't negate the potential risks present in the current code. Addressing the output escaping issues should be a priority to further harden the plugin's security.
Key Concerns
- 35% of outputs are not properly escaped
- No nonce checks implemented
CodeQuill Web to App Security Vulnerabilities
CodeQuill Web to App Code Analysis
Output Escaping
CodeQuill Web to App Attack Surface
WordPress Hooks 16
Maintenance & Trust
CodeQuill Web to App Maintenance & Trust
Maintenance Signals
Community Trust
CodeQuill Web to App Alternatives
WP-AppKit – Mobile apps and PWA for WordPress
wp-appkit
Important ✋: beginning with version 1.5.3, we don't support anymore native iOS app. This is a tough choice we explain here.
Progressify – All-in-One Progressive Web App (PWA) on Autopilot
progressify
Turn your site into an app-like PWA with install prompts, offline use, push notifications, and more to boost engagement, repeat visits, and sales.
Easy Progressive Web App
easy-progressive-web-app
Easy Progressive Web App
miTT PWA FREE WP
mitt-pwa
miTT PWA FREE WP transforms your WordPress Website into a Progressive Web App (PWA) and makes it offline ready using Service Workers.
Smart PWA Installer
smart-pwa-installer
Smart PWA Installer adds PWA support to your site with a floating install button and logs.
CodeQuill Web to App Developer Profile
1 plugin · 0 total installs
How We Detect CodeQuill Web to App
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/codequill-web-to-app/assets/css/admin.csscodequill-web-to-app/assets/css/admin.css?ver=HTML / DOM Fingerprints
codequill-pwa-wrapcodequill-pwa-cardcodequill-pwa-headercodequill-pwa-footercodequill-promo-wrapcodequill-promo-gridcodequill-promo-itemcodequill-promo-img+4 more