
Mobile Device Redirection Security & Risk Analysis
wordpress.org/plugins/mobile-device-redirectionThe Mobile Device Redirection plugin allows your Wordpress site to redirect to another url if a user visits it using a mobile device.
Is Mobile Device Redirection Safe to Use in 2026?
Generally Safe
Score 85/100Mobile Device Redirection has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mobile-device-redirection" plugin v0.1 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), file operations, and external HTTP requests are positive indicators. Furthermore, the lack of any recorded vulnerabilities in its history suggests a history of secure development or minimal exposure.
However, a significant concern arises from the output escaping. With one total output and 0% properly escaped, there's a clear risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is outputted directly to the browser without proper sanitization can be exploited. The absence of nonce checks and capability checks, while not directly tied to an identified attack vector in this specific analysis, represents a missed opportunity to bolster security for any potential future entry points.
In conclusion, while the plugin has a clean history and avoids common pitfalls like raw SQL or dangerous functions, the critical oversight in output escaping presents a tangible and exploitable security risk. Addressing the unescaped output is paramount to improving its security. The lack of checks for nonces and capabilities, though not currently exploitable, are areas for improvement to ensure robustness against future threats.
Key Concerns
- Unescaped output found
Mobile Device Redirection Security Vulnerabilities
Mobile Device Redirection Code Analysis
Output Escaping
Mobile Device Redirection Attack Surface
WordPress Hooks 3
Maintenance & Trust
Mobile Device Redirection Maintenance & Trust
Maintenance Signals
Community Trust
Mobile Device Redirection Alternatives
Photoswipe for NextGEN Gallery
photoswipe-for-nextgen-gallery
The default NextGEN gallery navigations (Shutter, Thickbox, etc...) fall short when using a mobile browser?
isMobile() Shortcode for WordPress
ismobile
This plugin works with the open source Mobile Detect Library. You can get further information on its website.
WPapptouch
wpapptouch
WPapptouch is a WordPress plugin & theme to transform your WordPress website to a Native like application for mobile.
Conditional Lightbox
conditional-lightbox
Use a lightbox only if the screen is big enough.
Mobile Device Detect Reloaded
mobile-device-detect-reloaded
This wordpress plugin allows to redirect visitors (desktop, mobile) to a custom target URL, which can be specified in admin.
Mobile Device Redirection Developer Profile
2 plugins · 9K total installs
How We Detect Mobile Device Redirection
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrapname="mobile_device_redirection_options[mobile_device_redirection_url]"