Mobile Smart App Banner Security & Risk Analysis

wordpress.org/plugins/mobile-smart-app-banner

Transform your mobile website visitors into app users with intelligent smart app banners that boost downloads across iOS and Android devices.

200 active installs v1.0.7 PHP 7.2+ WP 5.0+ Updated Mar 6, 2026
android-app-bannerapp-install-bannerios-app-bannermobile-app-promotionsmart-app-banner
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Mobile Smart App Banner Safe to Use in 2026?

Generally Safe

Score 100/100

Mobile Smart App Banner has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The 'mobile-smart-app-banner' plugin version 1.0.7 exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries, avoiding dangerous functions, performing file operations, or making external HTTP requests. The plugin also incorporates nonce checks and capability checks, which are crucial for securing WordPress functionality. However, a significant concern arises from the presence of an unprotected AJAX handler. This means that an attacker could potentially trigger this AJAX action without proper authentication, opening a door for unauthorized operations if the handler itself has vulnerabilities.

The static analysis reveals a small attack surface with only two entry points, but one of these is unprotected. The output escaping is reasonably good, with 81% of outputs properly escaped, but the remaining 19% could potentially lead to cross-site scripting (XSS) vulnerabilities if the unescaped data is user-controlled. Taint analysis shows no flows, which is a positive sign, suggesting that no obvious data sanitation issues were detected by the analysis tools in this regard. The vulnerability history is clean, with no known CVEs, indicating a lack of publicly disclosed vulnerabilities for this plugin, which generally suggests a history of good security maintenance.

In conclusion, while the plugin avoids several common pitfalls and has a clean vulnerability record, the unprotected AJAX handler is a critical weakness that needs immediate attention. The partially unescaped output also presents a potential risk. Addressing the unprotected AJAX endpoint and improving output escaping for the remaining percentage would significantly enhance the plugin's security posture. The absence of past vulnerabilities is encouraging, but it does not negate the risks identified in the current static analysis.

Key Concerns

  • Unprotected AJAX handler found
  • 19% of outputs are not properly escaped
Vulnerabilities
None known

Mobile Smart App Banner Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Mobile Smart App Banner Release Timeline

v1.0.7Current
v1.0.6
v1.0.5
v1.0.4
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Mobile Smart App Banner Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
24
101 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

81% escaped125 total outputs
Attack Surface
1 unprotected

Mobile Smart App Banner Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 2

authwp_ajax_msab_deactivate_feedbackadmin\class-mobile-smart-app-banner-deactivation-feedback.php:60
authwp_ajax_mobile_smart_app_banner_notice_actionmobile-smart-app-banner.php:143
WordPress Hooks 13
actioncurrent_screenadmin\class-mobile-smart-app-banner-deactivation-feedback.php:51
actionadmin_enqueue_scriptsadmin\class-mobile-smart-app-banner-deactivation-feedback.php:56
actionadmin_footeradmin\class-mobile-smart-app-banner-deactivation-feedback.php:78
actionadmin_noticesmobile-smart-app-banner.php:130
actionadmin_menumobile-smart-app-banner.php:133
actionadmin_initmobile-smart-app-banner.php:136
actionadmin_enqueue_scriptsmobile-smart-app-banner.php:139
actionadmin_enqueue_scriptsmobile-smart-app-banner.php:140
actionwp_enqueue_scriptsmobile-smart-app-banner.php:156
actionwp_enqueue_scriptsmobile-smart-app-banner.php:157
actionwp_footermobile-smart-app-banner.php:160
actionwp_headmobile-smart-app-banner.php:163
filteradmin_footer_textmobile-smart-app-banner.php:273
Maintenance & Trust

Mobile Smart App Banner Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 6, 2026
PHP min version7.2
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs200
Developer Profile

Mobile Smart App Banner Developer Profile

Jose Varghese

11 plugins · 3K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Mobile Smart App Banner

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mobile-smart-app-banner/public/css/mobile-smart-app-banner.css/wp-content/plugins/mobile-smart-app-banner/public/js/mobile-smart-app-banner.js
Script Paths
/wp-content/plugins/mobile-smart-app-banner/public/js/mobile-smart-app-banner.js
Version Parameters
mobile-smart-app-banner/public/css/mobile-smart-app-banner.css?ver=mobile-smart-app-banner/public/js/mobile-smart-app-banner.js?ver=

HTML / DOM Fingerprints

CSS Classes
mobile-smart-app-banner-containermsab-close-btnmsab-download-btn
Data Attributes
data-app-icondata-app-namedata-app-subtitledata-download-textdata-app-store-linkdata-play-store-link+7 more
JS Globals
msab_options
FAQ

Frequently Asked Questions about Mobile Smart App Banner