Mobile Booster Security & Risk Analysis

wordpress.org/plugins/mobile-booster

Need some help with the mobile website experience? Need to keep your mobile visitors engaged? Need to increase your shop website sales conversion?

10 active installs v1.2.1 PHP 5.6+ WP 4.0+ Updated Mar 27, 2022
ecommercelazyloadmobileprefetchquicklink
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Mobile Booster Safe to Use in 2026?

Generally Safe

Score 85/100

Mobile Booster has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The static analysis of "mobile-booster" v1.2.1 reveals a seemingly robust security posture, with no identified attack vectors through AJAX handlers, REST API routes, shortcodes, or cron events. The code also shows a positive trend in using prepared statements for all SQL queries, which is a significant defense against SQL injection. However, the low percentage of properly escaped output (29%) is a notable concern, indicating potential cross-site scripting (XSS) vulnerabilities. The absence of any identified dangerous functions or taint analysis findings is positive, but this could be partly due to the limited scope of the analysis or the plugin's functionality.

The vulnerability history is remarkably clean, with no recorded CVEs. This, combined with the absence of critical or high severity findings in the static analysis, suggests a history of relatively secure development. However, the complete lack of known vulnerabilities might also indicate that the plugin has not been extensively targeted or that its functionality is limited. The bundled Freemius library, while present, is not explicitly flagged as outdated in the provided data, but any bundled libraries should be regularly monitored for security updates.

In conclusion, "mobile-booster" v1.2.1 demonstrates good practices in areas like SQL handling and attack surface minimization. The primary weakness lies in the insufficient output escaping, which presents a tangible risk of XSS. The absence of past vulnerabilities is a strength, but it should not lead to complacency, especially given the identified output escaping issues.

Key Concerns

  • Insufficient output escaping
  • Bundled library (Freemius v1.0) without version check
Vulnerabilities
None known

Mobile Booster Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Mobile Booster Release Timeline

v1.2.1Current
v1.2
v1.1
v1.0
Code Analysis
Analyzed Mar 17, 2026

Mobile Booster Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

29% escaped7 total outputs
Attack Surface

Mobile Booster Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
filterwp_headincludes\class-wp-mobile-booster-core.php:24
filterwp_footerincludes\class-wp-mobile-booster-core.php:31
filterthe_contentincludes\class-wp-mobile-booster-core.php:34
filterwp_headincludes\class-wp-mobile-booster-core.php:43
actionadmin_menuincludes\class-wp-mobile-booster-options.php:19
actionafter_uninstallmobile-booster.php:44
actioncustomize_registermobile-booster.php:53
actionwp_footermobile-booster.php:108
actionwp_enqueue_scriptsmobile-booster.php:111
Maintenance & Trust

Mobile Booster Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedMar 27, 2022
PHP min version5.6
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Mobile Booster Developer Profile

Rui Guerreiro

4 plugins · 180K total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
421 days
View full developer profile
Detection Fingerprints

How We Detect Mobile Booster

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mobile-booster/css/mobile-booster.css/wp-content/plugins/mobile-booster/js/mobile-booster.js/wp-content/plugins/mobile-booster/js/quicklink.umd.js/wp-content/plugins/mobile-booster/includes/assets/placeholder.gif
Script Paths
https://cdn.jsdelivr.net/npm/lozad/dist/lozad.min.js
Version Parameters
mobile-booster/css/mobile-booster.css?ver=mobile-booster/js/mobile-booster.js?ver=

HTML / DOM Fingerprints

CSS Classes
mob-booster-footerlozad
Data Attributes
data-srcdata-srcsetdata-sizes
JS Globals
lozadquicklink
Shortcode Output
<div class="mob-booster-footer"> <a href=
FAQ

Frequently Asked Questions about Mobile Booster