Create my Apps Security & Risk Analysis

wordpress.org/plugins/create-my-apps

WP to App and WooCommerce to App is absolutely easy with the App Builder software from https://create-my-apps.com without programming knowledge.

10 active installs v1.2.5 PHP + WP 4.3+ Updated Jul 8, 2017
app-builderapp-creatorwoocommerce-to-appwordpress-to-appwp-to-app
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Create my Apps Safe to Use in 2026?

Generally Safe

Score 85/100

Create my Apps has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The 'create-my-apps' plugin version 1.2.5 exhibits a seemingly robust security posture based on the provided static analysis. There are no identified entry points that are unprotected, and the code does not appear to use dangerous functions, perform file operations, or make external HTTP requests. Furthermore, all SQL queries are properly prepared, which is a significant strength. The absence of any reported vulnerabilities in its history is also a positive indicator of past security diligence.

However, a critical concern arises from the output escaping analysis, where 100% of outputs are not properly escaped. This represents a significant risk, as it can lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled correctly before being displayed. The lack of any nonce or capability checks, while not directly tied to identified entry points in this analysis, suggests a potential weakness if new entry points were to be introduced or if existing ones were overlooked. The fact that no taint flows were found is good, but this could be due to the limited attack surface analyzed or the absence of data processing that would trigger taint analysis.

In conclusion, while the plugin avoids common pitfalls like raw SQL and direct access to entry points, the pervasive issue of unescaped output presents a clear and present danger. This weakness, coupled with the absence of nonce and capability checks, necessitates caution. The plugin's clean vulnerability history is a positive, but it should not overshadow the identified risks within the current code.

Key Concerns

  • Output escaping is not used
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Create my Apps Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Create my Apps Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Create my Apps Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Create my Apps Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_noticesapp-creator.php:25
filterrewrite_rules_arrayapp-creator.php:39
actioninitapp-creator.php:49
actiontemplate_redirectmodels\connector.php:22
Maintenance & Trust

Create my Apps Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedJul 8, 2017
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Create my Apps Developer Profile

Create my Apps

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Create my Apps

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/create-my-apps/models/default.php/wp-content/plugins/create-my-apps/models/connector.php

HTML / DOM Fingerprints

CSS Classes
app-creator-warning
FAQ

Frequently Asked Questions about Create my Apps