
isMobile() Shortcode for WordPress Security & Risk Analysis
wordpress.org/plugins/ismobileThis plugin works with the open source Mobile Detect Library. You can get further information on its website.
Is isMobile() Shortcode for WordPress Safe to Use in 2026?
Generally Safe
Score 99/100isMobile() Shortcode for WordPress has a strong security track record. Known vulnerabilities have been patched promptly.
The 'ismobile' plugin v1.1.2 exhibits a generally strong security posture based on the provided static analysis. The code demonstrates excellent practices, with 100% of SQL queries utilizing prepared statements and all output properly escaped. The presence of nonce and capability checks further bolsters its defense against common web vulnerabilities. The absence of file operations and external HTTP requests reduces the potential attack surface in these areas. While the attack surface is minimal with only one shortcode, the lack of any identified taint flows is a positive indicator, suggesting that input sanitization and handling are likely robust.
However, a significant concern arises from the plugin's vulnerability history. The presence of one known CVE, even if currently unpatched (meaning a patch exists), points to past security weaknesses. The common vulnerability type identified as Cross-site Scripting is particularly noteworthy, as it indicates that improper input neutralization has been an issue in the past. While the latest vulnerability is dated in the future (2025-06-26), this might be a data anomaly or indicate a future discovery. The fact that there are no currently unpatched vulnerabilities is a mitigating factor, but the past occurrence of XSS warrants caution.
In conclusion, 'ismobile' v1.1.2 benefits from a well-written codebase with strong adherence to secure coding practices. Its minimal attack surface and proper handling of sensitive operations are commendable. The primary weakness lies in its past vulnerability to Cross-site Scripting. Users should ensure they are using the absolute latest version of the plugin where any discovered vulnerabilities are patched. The static analysis is overwhelmingly positive, but the historical CVE cannot be ignored.
Key Concerns
- Known CVE exists (though patched)
- Past vulnerability to XSS
isMobile() Shortcode for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
isMobile <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via device Parameter
isMobile() Shortcode for WordPress Code Analysis
Output Escaping
isMobile() Shortcode for WordPress Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
isMobile() Shortcode for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
isMobile() Shortcode for WordPress Alternatives
Mobile Detect
tinywp-mobile-detect
Fine-tunes wp_is_mobile function by excluding tablets (ex: iPad), from being detected as mobile! Uses MobileDetect PHP Library from mobiledetect.net!
WP Mobile Redirect
mobile-redirect-plus-lite
Detect mobile device and redirect to mobile optimize website. You can also choose whether or not to redirect tablets by enabling or disabling the chec …
Photoswipe for NextGEN Gallery
photoswipe-for-nextgen-gallery
The default NextGEN gallery navigations (Shutter, Thickbox, etc...) fall short when using a mobile browser?
Add Device Type to Body Class
add-device-type-to-body-class
This plugin is used to add type of device (mobile, tablet, desktop) in body class of wordpress website. This class is used to add device specific CSS.
WPapptouch
wpapptouch
WPapptouch is a WordPress plugin & theme to transform your WordPress website to a Native like application for mobile.
isMobile() Shortcode for WordPress Developer Profile
2 plugins · 190 total installs
How We Detect isMobile() Shortcode for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
ismobile-headingismobile-subshortcodecardtitlewis_detect[ismobile device='iphone' debug=false ] Your content [/ismobile]