Mobile APP Dashboard Custom Fields Json API Security & Risk Analysis

wordpress.org/plugins/mobile-app-dashboard-custom-fields-json-api

Plugin for provide Configuration page or Dashboard for your mobile APP so you can add custom fields as many as you want and get data in Jason API.

10 active installs v1.1 PHP + WP 3.0.1+ Updated Dec 30, 2018
dashboardjson_apimobilemobileappmobile_app_dashboard
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Mobile APP Dashboard Custom Fields Json API Safe to Use in 2026?

Generally Safe

Score 85/100

Mobile APP Dashboard Custom Fields Json API has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The plugin "mobile-app-dashboard-custom-fields-json-api" v1.1 exhibits a concerning security posture despite having no recorded vulnerabilities or apparent attack surface through common entry points like AJAX, REST API, or shortcodes. The static analysis reveals significant weaknesses, particularly in data handling. All SQL queries (3 in total) are executed without prepared statements, a major risk for SQL injection vulnerabilities. Furthermore, none of the 14 identified output operations are properly escaped, creating a high probability of Cross-Site Scripting (XSS) attacks. The taint analysis highlights one flow with unsanitized paths, classified as high severity, which strongly suggests a pathway for malicious data to be processed without adequate sanitization. While the absence of external HTTP requests and file operations is a positive sign, the lack of capability checks and nonce checks on potential backend operations, combined with the unescaped outputs and raw SQL, presents substantial risks. The plugin's history of zero CVEs is positive but cannot be relied upon given the current code analysis findings. It's crucial to address the identified SQL and output escaping issues proactively.

Key Concerns

  • Raw SQL queries without prepared statements
  • No output escaping
  • High severity unsanitized taint flow
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Mobile APP Dashboard Custom Fields Json API Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Mobile APP Dashboard Custom Fields Json API Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
0 prepared
Unescaped Output
14
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared3 total queries

Output Escaping

0% escaped14 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<custom_json_api_single> (include\custom_json_api_single.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Mobile APP Dashboard Custom Fields Json API Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actioninitappconfigurator.php:15
filtersingle_templateappconfigurator.php:38
actionadmin_menuappconfigurator.php:46
actionadmin_enqueue_scriptsappconfigurator.php:51
actionadmin_enqueue_scriptsappconfigurator.php:57
actionadmin_footerinclude\config_page.php:86
Maintenance & Trust

Mobile APP Dashboard Custom Fields Json API Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedDec 30, 2018
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Mobile APP Dashboard Custom Fields Json API Developer Profile

mainsufian

3 plugins · 620 total installs

79
trust score
Avg Security Score
78/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Mobile APP Dashboard Custom Fields Json API

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mobile-app-dashboard-custom-fields-json-api/css/app_admin_style.css/wp-content/plugins/mobile-app-dashboard-custom-fields-json-api/js/app_admin_js.js
Script Paths
/wp-content/plugins/mobile-app-dashboard-custom-fields-json-api/js/app_admin_js.js
Version Parameters
mobile-app-dashboard-custom-fields-json-api/css/app_admin_style.css?ver=1.0.0mobile-app-dashboard-custom-fields-json-api/js/app_admin_js.js

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Mobile APP Dashboard Custom Fields Json API