Connector for Mobilizon Security & Risk Analysis

wordpress.org/plugins/connector-mobilizon

Display Mobilizon events in WordPress.

20 active installs v2.2.0 PHP 7.4+ WP 5.6+ Updated Jan 21, 2026
eventsmobilizon
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Connector for Mobilizon Safe to Use in 2026?

Generally Safe

Score 100/100

Connector for Mobilizon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The static analysis of connector-mobilizon v2.2.0 reveals a generally positive security posture. The plugin demonstrates good practices by ensuring all SQL queries utilize prepared statements and all output is properly escaped. Furthermore, the absence of known vulnerabilities in its history, including no recorded CVEs, suggests a mature and well-maintained codebase. The limited attack surface, with no apparent unprotected entry points, further contributes to its secure design.

However, there are a few areas that warrant attention. The presence of one file operation and one external HTTP request, while not inherently insecure, represents potential vectors for vulnerabilities if not handled with extreme care and robust sanitization. The absence of nonce checks on any entry points, coupled with only two capability checks across the entire codebase, is a significant concern. This indicates a potential weakness in ensuring actions are authorized and preventing cross-site request forgery (CSRF) or unauthorized privilege escalation.

In conclusion, while connector-mobilizon v2.2.0 exhibits strong foundational security practices, the lack of comprehensive authorization checks and the potential risks associated with file operations and external requests suggest that further scrutiny and potential improvements are recommended. The absence of known vulnerabilities is a positive indicator, but the identified weaknesses in authorization and the handling of external interactions are areas that could be exploited.

Key Concerns

  • No nonce checks on entry points
  • Limited capability checks (2 total)
  • One file operation detected
  • One external HTTP request detected
Vulnerabilities
None known

Connector for Mobilizon Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Connector for Mobilizon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
91 escaped
Nonce Checks
0
Capability Checks
2
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped91 total outputs
Attack Surface

Connector for Mobilizon Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actioninitconnector-mobilizon.php:37
actioninitconnector-mobilizon.php:38
actioninitconnector-mobilizon.php:39
actioninitconnector-mobilizon.php:40
actionwidgets_initconnector-mobilizon.php:41
filterplugin_row_metaconnector-mobilizon.php:43
filterplugin_action_links_connector-mobilizon/connector-mobilizon.phpconnector-mobilizon.php:44
actionrest_api_initincludes\Api.php:11
actionadmin_initincludes\Settings.php:21
actionadmin_menuincludes\Settings.php:22
Maintenance & Trust

Connector for Mobilizon Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 21, 2026
PHP min version7.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Connector for Mobilizon Developer Profile

Daniel

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Connector for Mobilizon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/connector-mobilizon/build/index.css/wp-content/plugins/connector-mobilizon/build/index.js
Script Paths
/wp-content/plugins/connector-mobilizon/build/index.js
Version Parameters
connector-mobilizon/build/index.js?ver=connector-mobilizon/build/index.css?ver=

HTML / DOM Fingerprints

CSS Classes
mobilizon-connector-events-listmobilizon-connector-event-itemmobilizon-connector-event-datemobilizon-connector-event-timemobilizon-connector-event-titlemobilizon-connector-event-descriptionmobilizon-connector-event-organizermobilizon-connector-event-location+1 more
Data Attributes
data-mobilizon-urldata-mobilizon-events-countdata-mobilizon-group-name
JS Globals
MOBILIZON_CONNECTOR
REST Endpoints
/wp-json/mobilizon-connector/v1/events
Shortcode Output
[mobilizon-connector-events-list]
FAQ

Frequently Asked Questions about Connector for Mobilizon