
ShopApper: Mobile App for WooCommerce Security & Risk Analysis
wordpress.org/plugins/mobile-app-for-woocommerceNative iOS & Android mobile app for your WooCommerce store customers. Build a fully functional, customizable native app within minutes.
Is ShopApper: Mobile App for WooCommerce Safe to Use in 2026?
Mostly Safe
Score 78/100ShopApper: Mobile App for WooCommerce is generally safe to use. 1 past CVE were resolved. Keep it updated.
The "mobile-app-for-woocommerce" plugin v0.4.61 demonstrates a generally good security posture with several positive indicators. All SQL queries are prepared, and a high percentage of output is properly escaped, mitigating common injection and XSS risks. The plugin also implements nonce and capability checks, and its attack surface through AJAX, REST API, and shortcodes appears to be minimal or protected. However, there are two concerning taint analysis flows that were identified with unsanitized paths, though they are not categorized as critical or high severity. This suggests a potential for subtle vulnerabilities that could be exploited if user input is not handled with extreme care.
The plugin's vulnerability history is a significant concern, with one medium severity CVE that remains unpatched. The fact that the last vulnerability was reported very recently (2025-04-14) and is still unpatched indicates a potential for delayed or inadequate security maintenance. The common vulnerability type being Cross-site Scripting further reinforces the need for vigilance in output escaping and input sanitization, even with the current high escaping rate. While the plugin has strengths in its secure coding practices, the presence of unsanitized taint flows and a recent, unpatched vulnerability necessitates a cautious approach.
Key Concerns
- Unpatched CVE detected
- Taint analysis with unsanitized paths
- Bundled library Guzzle detected
ShopApper: Mobile App for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
ShopApper <= 0.4.53 - Unauthenticated Stored Cross-Site Scripting
ShopApper: Mobile App for WooCommerce Release Timeline
ShopApper: Mobile App for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
ShopApper: Mobile App for WooCommerce Attack Surface
WordPress Hooks 103
Scheduled Events 1
Maintenance & Trust
ShopApper: Mobile App for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
ShopApper: Mobile App for WooCommerce Alternatives
Mobile builder
mobile-builder
The most advanced drag & drop app builder. Create multi templates and app controls.
AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker)
appmysite
Turn your WordPress or WooCommerce site into a native Android & iOS app in minutes — no coding required.
MStore API – Create Native Android & iOS Apps On The Cloud
mstore-api
Take your WordPress store mobile with MStore API! This plugin bridges the gap between your WordPress website and the powerful FluxBuilder app builder.
Taqnix
taqnix
Build AI-powered mobile apps for WordPress/WooCommerce. No code, 100+ templates, push alerts, payments. Launch in minutes.
TC Ecommerce – Create Android & iOS Apps for WooCommerce
tc-ecommerce
TC eCommerce Plugin is complete mobile app solution for android and iOS platform with WordPress WooCommerce as backend.
ShopApper: Mobile App for WooCommerce Developer Profile
3 plugins · 80 total installs
How We Detect ShopApper: Mobile App for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mobile-app-for-woocommerce/assets/css/visibility.css/wp-content/plugins/mobile-app-for-woocommerce/assets/js/app.js/wp-content/plugins/mobile-app-for-woocommerce/assets/js/app.jsmobile-app-for-woocommerce/assets/css/visibility.css?ver=mobile-app-for-woocommerce/assets/js/app.js?ver=HTML / DOM Fingerprints
shopapper-visibilityshopapper_product_dataterm-shopapper_hideHide product from app?Product appears on the web but it prevents users from adding it to cart.It entirely hides the product from the web.Hide attribute from app?shopapper_hideshopapper_only_appshopapper_hide_webMAFW_PATHMAFW_URLMAFW_BASENAMEMAFW_WC_API_KEY_TABLEMAFW_CLIENT_ROUTEshopapper/client/v1