
Device Mockups Security & Risk Analysis
wordpress.org/plugins/device-mockupsShow your work in high resolution, responsive device mockups using only shortcodes.
Is Device Mockups Safe to Use in 2026?
Generally Safe
Score 85/100Device Mockups has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "device-mockups" plugin v1.8.2 demonstrates a strong security posture based on the provided static analysis. It correctly utilizes prepared statements for all SQL queries and ensures all output is properly escaped, mitigating common web vulnerabilities like SQL injection and Cross-Site Scripting. The absence of dangerous functions, file operations, and external HTTP requests further enhances its security. The plugin also implements capability checks on its entry points, which is a good practice for restricting access. However, a notable concern is the lack of nonce checks on its entry points (shortcodes). While the analysis indicates no exploitable taint flows or known CVEs, the absence of nonces on shortcodes, which are user-facing and can be triggered programmatically, presents a potential risk for Cross-Site Request Forgery (CSRF) attacks. The plugin's history of zero vulnerabilities is a positive indicator, suggesting the developers prioritize security. Despite the strong foundations, the missing nonce checks represent a weakness that should be addressed to achieve a more robust security profile.
Key Concerns
- Missing nonce checks on shortcodes
Device Mockups Security Vulnerabilities
Device Mockups Code Analysis
Output Escaping
Device Mockups Attack Surface
Shortcodes 2
WordPress Hooks 10
Maintenance & Trust
Device Mockups Maintenance & Trust
Maintenance Signals
Community Trust
Device Mockups Alternatives
Mockups
mockups
Mockup Blocks for WordPress Gutenberg featuring 6 free iPhone X mockup photos.
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
Devices for Elementor
devices-elementor
Devices for Elementor is a powerful Elementor widget that lets you add a phone, tablet, laptop, desktop or window / browser frame to your images or sc …
Device Wrapper
device-wrapper
A WordPress plugin which enables users to wrap an image, video or iframe into a device mockup.
Inline Video Shortcodes
inline-video-shortcodes
Extends the built-in Wordpress video shortcode with 'muted' and 'playsinline' attributes to enabline inline and automatic html5 vi …
Device Mockups Developer Profile
2 plugins · 910 total installs
How We Detect Device Mockups
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/device-mockups/css/device-mockups.css/wp-content/plugins/device-mockups/js/device-mockups.js/wp-content/plugins/device-mockups/admin/device-mockups.css/wp-content/plugins/device-mockups/js/device-mockups.jsdevice-mockups/css/device-mockups.css?ver=device-mockups/js/device-mockups.js?ver=device-mockups-admin.css?ver=HTML / DOM Fingerprints
dm-browserscreenhas-gallerydm-scrolldm-widthdevicedm-devicedm-hide-+1 more/.screen -->/.device -->/.dm-browser -->/.dm-width -->data-device[browser[device