
WP Mobile Redirect Security & Risk Analysis
wordpress.org/plugins/mobile-redirect-plus-liteDetect mobile device and redirect to mobile optimize website. You can also choose whether or not to redirect tablets by enabling or disabling the chec …
Is WP Mobile Redirect Safe to Use in 2026?
Generally Safe
Score 92/100WP Mobile Redirect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "mobile-redirect-plus-lite" v2.6 exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its potential attack surface. Furthermore, the code signals show no dangerous functions, all SQL queries utilize prepared statements, and there are no file operations or external HTTP requests. The lack of recorded vulnerabilities in its history reinforces this positive outlook.
However, a notable concern arises from the low percentage of properly escaped output (18%). This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data might be rendered directly in the browser without adequate sanitization. While no taint analysis flows indicate immediate critical or high severity issues, the insufficient output escaping presents a tangible risk that could be exploited if an attacker can inject malicious scripts through other means not immediately apparent in this analysis. The complete absence of nonce checks and capability checks, while not directly linked to an exploitable condition in this snapshot, represents a missed opportunity for robust access control on potential future entry points.
In conclusion, the plugin is largely well-secured with a minimal attack surface and good database practices. The primary weakness lies in the inadequate output escaping, which poses a moderate XSS risk. While there are no historical vulnerabilities, the observed code quality issue warrants attention to prevent future security incidents.
Key Concerns
- Low output escaping rate
- Missing nonce checks
- Missing capability checks
WP Mobile Redirect Security Vulnerabilities
WP Mobile Redirect Code Analysis
Output Escaping
WP Mobile Redirect Attack Surface
WordPress Hooks 4
Maintenance & Trust
WP Mobile Redirect Maintenance & Trust
Maintenance Signals
Community Trust
WP Mobile Redirect Alternatives
Equivalent Mobile Redirect
equivalent-mobile-redirect
Easy way to detect and redirect mobile visitors to the equivalent page on your mobile site. Optionally redirect all mobile users to one mobile URL.
Device-Based Redirect
device-based-redirect
Redirect users to your app pages in app store or play store based on their device type with custom URLs and page-specific redirects.
Multi Mobile Redirect
multi-mobile-redirect
Multi Mobile Redirect allows to set up redirect for any url to mobile version of the page. You can setup multiple redirects per page.
Mobile Redirect For Pages and Posts
mobile-redirection-for-pages-and-posts
This Plugin lets you redirect the visitors to a specific URL when the page/post is viewed from a mobile device. You can specify on which URL you want …
Average Mobile Detect
average-mobile-detect
Redirects mobile traffic to mobile site, allows visitors to opt for desktop site, provides shortcodes and widget to generate links to mobile site
WP Mobile Redirect Developer Profile
1 plugin · 500 total installs
How We Detect WP Mobile Redirect
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mobile-redirect-plus-lite/includes/mobile-plus-redirect-lite.css/wp-content/plugins/mobile-redirect-plus-lite/includes/mobile-plus-redirect-lite.jsmobile-redirect-plus-lite/includes/mobile-plus-redirect-lite.css?ver=mobile-redirect-plus-lite/includes/mobile-plus-redirect-lite.js?ver=