MobiKoB Security & Risk Analysis

wordpress.org/plugins/mobikob

MobiKoB eklentisi ile, MobiKoB hesabınızla;

0 active installs v1.0.3 PHP 5.6+ WP 3.0+ Updated Dec 11, 2023
bulk-smssahratelekom-wordpresssms-turkiyetoplu-smswoocommerce-sms
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MobiKoB Safe to Use in 2026?

Generally Safe

Score 85/100

MobiKoB has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The mobikob plugin v1.0.3 presents a significant security risk primarily due to its unprotected attack surface. With 8 AJAX handlers identified, all of which lack any authentication or authorization checks, an unauthenticated attacker could potentially trigger these functions and execute arbitrary code or manipulate plugin behavior. While the plugin demonstrates good practices in its SQL query handling (100% prepared statements) and a high percentage of output escaping (93%), these strengths are overshadowed by the critical vulnerability of exposed AJAX endpoints. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator of past security consciousness. However, this lack of historical vulnerabilities does not negate the immediate and severe risks posed by the current code analysis. The absence of capability checks and nonce checks on the exposed AJAX handlers further exacerbates the situation, making them prime targets for exploitation. In conclusion, while the plugin exhibits some positive security attributes, the unprotected AJAX handlers represent a critical flaw that necessitates immediate attention and remediation.

Key Concerns

  • AJAX handlers without auth checks
  • Missing capability checks on AJAX
  • Missing nonce checks on AJAX
Vulnerabilities
None known

MobiKoB Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

MobiKoB Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

MobiKoB Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
15
202 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
5
Bundled Libraries
1

Bundled Libraries

DataTables

SQL Query Safety

100% prepared2 total queries

Output Escaping

93% escaped217 total outputs
Attack Surface
8 unprotected

MobiKoB Attack Surface

Entry Points8
Unprotected8

AJAX Handlers 8

authwp_ajax_sahra_addtoGroupindex.php:593
authwp_ajax_add_crm_one_personindex.php:636
authwp_ajax_sahra_sendSMS_bulkTabindex.php:693
authwp_ajax_sahra_MakeCallindex.php:742
authwp_ajax_make_call_with_devicesindex.php:765
authwp_ajax_sahra_sendsmsindex.php:804
authwp_ajax_sahra_sendtf2SMSindex.php:939
noprivwp_ajax_sahra_sendtf2SMSindex.php:1054
WordPress Hooks 22
actionadmin_menuindex.php:38
actionadmin_enqueue_scriptsindex.php:57
actionadmin_enqueue_scriptsindex.php:71
actionadmin_initindex.php:91
actionadmin_footerindex.php:219
filtersahra_contact_form_7_listindex.php:680
actionwoocommerce_register_formindex.php:862
actionwp_enqueue_scriptsindex.php:1053
filterwoocommerce_process_registration_errorsindex.php:1066
actionwoocommerce_created_customerindex.php:1126
actionlmfwc_event_post_order_license_keysindex.php:1191
actionwoocommerce_payment_completeindex.php:1214
actionwoocommerce_thankyouindex.php:1215
actionwp_insert_postindex.php:1221
actionwoocommerce_order_status_changedindex.php:1333
actionwoocommerce_order_status_cancelledindex.php:1335
filterwoocommerce_customer_save_addressindex.php:1365
actionwoocommerce_new_order_note_dataindex.php:1486
actionwoocommerce_product_set_stockindex.php:1563
actionwoocommerce_variation_set_stockindex.php:1571
actionwcwl_mailout_send_emailindex.php:1601
filterwoocommerce_rest_api_get_rest_namespacesindex.php:1673
Maintenance & Trust

MobiKoB Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedDec 11, 2023
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

MobiKoB Developer Profile

mobikob

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MobiKoB

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mobikob/lib/css/bootstrap.css/wp-content/plugins/mobikob/lib/fonts/css/font-awesome.min.css/wp-content/plugins/mobikob/lib/css/style.css/wp-content/plugins/mobikob/lib/js/sweetalert2/dist/sweetalert2.css/wp-content/plugins/mobikob/lib/css/bootstrap-table.min.css
Script Paths
/wp-content/plugins/mobikob/lib/js/sweetalert2/dist/1/sweetalert2.all.js/wp-content/plugins/mobikob/bootstrap.min.js/wp-content/plugins/mobikob/lib/js/1/bootstrap-table.min.js
Version Parameters
mobikob/style.css?ver=mobikob/bootstrap.min.js?ver=mobikob/sweetalert2.all.js?ver=mobikob/bootstrap-table.min.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about MobiKoB