Easy Progressive Web App Security & Risk Analysis

wordpress.org/plugins/easy-progressive-web-app

Easy Progressive Web App

20 active installs v1.3 PHP + WP 4.6+ Updated Unknown
manifestmobile-appprogressive-web-apppwaweb-manifest
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Easy Progressive Web App Safe to Use in 2026?

Generally Safe

Score 100/100

Easy Progressive Web App has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The 'easy-progressive-web-app' plugin version 1.3 presents a mixed security posture. On the positive side, it demonstrates good practices in its handling of SQL queries, exclusively using prepared statements, and a very high percentage of properly escaped output, mitigating common risks like SQL injection and XSS. The absence of known CVEs and a clean vulnerability history further suggests a relatively secure past. However, significant concerns arise from the identified attack surface. With two AJAX handlers and none of them protected by authentication checks, these entry points are highly vulnerable to unauthorized access and potential exploitation. While taint analysis shows no current critical or high severity flows, the unprotected AJAX endpoints could be leveraged to trigger unintended actions or expose sensitive data if malicious input is not properly validated within the handler itself.

Despite the plugin's adherence to secure coding for database operations and output, the lack of authentication on its AJAX endpoints is a critical weakness. This creates a substantial risk of unauthorized actions being performed by unauthenticated users. The plugin's vulnerability history is clean, which is positive, but this does not negate the immediate risk posed by the unprotected AJAX handlers. In conclusion, while the plugin has strengths in its data handling, the exposed AJAX entry points represent a significant security flaw that requires immediate attention to prevent potential compromise.

Key Concerns

  • AJAX handlers without authentication
  • Total entry points without auth
Vulnerabilities
None known

Easy Progressive Web App Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Easy Progressive Web App Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
109 escaped
Nonce Checks
1
Capability Checks
1
File Operations
1
External Requests
3
Bundled Libraries
0

Output Escaping

97% escaped112 total outputs
Attack Surface
2 unprotected

Easy Progressive Web App Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

noprivwp_ajax_save_android_countqe-pwa.php:59
authwp_ajax_save_android_countqe-pwa.php:60
WordPress Hooks 11
actionadmin_initinc\QEApps-pwa-admin.php:167
actionwp_headinc\QEApps-pwa-manifest.php:29
actionadmin_initqe-pwa.php:50
actionadmin_enqueue_scriptsqe-pwa.php:51
actionadmin_enqueue_scriptsqe-pwa.php:52
actionwp_headqe-pwa.php:53
actionwp_footerqe-pwa.php:54
actionwp_enqueue_scriptsqe-pwa.php:55
actionadmin_menuqe-pwa.php:56
actioninitqe-pwa.php:57
actionadmin_post_qeappspwa_supportqe-pwa.php:58
Maintenance & Trust

Easy Progressive Web App Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedUnknown
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

Easy Progressive Web App Developer Profile

qeapps

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Easy Progressive Web App

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easy-progressive-web-app/css/qeapps_pwa_style.css/wp-content/plugins/easy-progressive-web-app/css/qeapps_pwa_front_style.css/wp-content/plugins/easy-progressive-web-app/js/qeapps_pwa_script.js
Script Paths
/wp-content/plugins/easy-progressive-web-app/js/qeapps_pwa_script.js
Version Parameters
qeapps-pwa-js?ver=1.0qeapps-pwa-css?ver=1.0.0

HTML / DOM Fingerprints

JS Globals
deferredPromptQEAPPS_VERSIONQEAPPS_PATH_SRCQEAPPS_PLUGIN_FILEQEAPPS_SPLASH_ICONQEAPPS_APPLICATION_ICON
FAQ

Frequently Asked Questions about Easy Progressive Web App