
IamMobiled Mobile Security & Risk Analysis
wordpress.org/plugins/iammobiled-mobileIamMobiled Mobile Plugin enables your mobile users to see a mobile theme of your website. Comes with a mobile specific theme "Blue Heart"
Is IamMobiled Mobile Safe to Use in 2026?
Generally Safe
Score 100/100IamMobiled Mobile has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "iammobiled-mobile" v1.0 plugin exhibits a mixed security posture. On the positive side, the static analysis indicates a very small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events exposed. This significantly limits direct avenues for attackers to interact with the plugin. Furthermore, the plugin has no recorded vulnerability history, which suggests a relatively stable and perhaps well-maintained codebase in terms of known security flaws.
However, there are significant concerns within the code itself. The presence of the `create_function` call is a major red flag, as it is deprecated and can be a source of remote code execution vulnerabilities if not handled with extreme care and sanitization. The complete lack of prepared statements for all SQL queries is another critical issue, making the plugin highly susceptible to SQL injection attacks. Additionally, a low percentage of properly escaped output (15%) suggests a high risk of cross-site scripting (XSS) vulnerabilities across various output points. While taint analysis didn't reveal critical or high severity issues, the presence of unsanitized paths warrants further investigation.
In conclusion, while the limited attack surface and lack of historical vulnerabilities are strengths, the identified code quality issues, particularly the use of `create_function`, the complete absence of prepared statements for SQL, and poor output escaping, represent substantial security risks. These weaknesses could be exploited to compromise the WordPress site.
Key Concerns
- Uses create_function()
- All SQL queries use raw SQL
- Low percentage of properly escaped output
- Flows with unsanitized paths
- No nonce checks
IamMobiled Mobile Security Vulnerabilities
IamMobiled Mobile Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
IamMobiled Mobile Attack Surface
WordPress Hooks 12
Maintenance & Trust
IamMobiled Mobile Maintenance & Trust
Maintenance Signals
Community Trust
IamMobiled Mobile Alternatives
BAAP Mobile Version
baap-mobile-version
The BAAP Mobile Version is a complete toolkit to help mobilize your WordPress site. It has a mobile switcher, themes, widgets, and mobile admin panel.
Business Profile Extra Fields
business-profile-extra-fields
You need the Five star business profile plugin to use this plugin
MoFuse WordPress Plugin
mofuse
Requires at least 2.0.2 Test up to: 2.7.1 Stable tag: 2.7.1 This plugin works with a MoFuse account. This plugin will automatically detect and redir …
Wireless-WordPress
wireless-wordpress
Wireless WordPress插件可以为你的博客增加友好的手机版页面
WPtouch – Make your WordPress Website Mobile-Friendly
wptouch
With just a few clicks, make your WordPress website mobile-friendly (iPhone, Android, and more). Recommended by Google, it will instantly enable a mob …
IamMobiled Mobile Developer Profile
1 plugin · 10 total installs
How We Detect IamMobiled Mobile
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/iammobiled-mobile/css/style.css/wp-content/plugins/iammobiled-mobile/js/script.js/wp-content/plugins/iammobiled-mobile/js/script.jsiammobiled-mobile/css/style.css?ver=iammobiled-mobile/js/script.js?ver=HTML / DOM Fingerprints
centered<!-- IamMobiled Mobile --><!-- Copyright (c) 2009 IamMobiled.com --><!-- http://iammobiled.com --><!-- Released under the GPL license -->+6 moredata-cf-mobile