
Mobile WP Security Security & Risk Analysis
wordpress.org/plugins/mobile-wp-securityThis plugin exposes the rest APIs to be able to control some aspects of wordpress security via the mobile app "Mobile Security for Wordpress" …
Is Mobile WP Security Safe to Use in 2026?
Generally Safe
Score 85/100Mobile WP Security has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mobile-wp-security" v1.2.0 plugin presents a generally positive security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points indicates a limited attack surface. Furthermore, the lack of critical or high severity taint flows is a strong indicator that sensitive data is likely being handled with caution. The vulnerability history being clear of any known CVEs also contributes to a perception of low risk.
However, several areas warrant attention and slightly temper the otherwise positive outlook. The moderate percentage of SQL queries not using prepared statements (69% not prepared) is a concern, as this could lead to SQL injection vulnerabilities if the inputs are not meticulously sanitized. Similarly, the low percentage of properly escaped output (57% not escaped) raises red flags for potential Cross-Site Scripting (XSS) vulnerabilities. The complete absence of nonce checks and capability checks on any entry points, although the entry points themselves are currently listed as zero, is a systemic weakness. If any entry points were to be introduced or discovered, they would likely be unprotected. The presence of file operations and external HTTP requests without explicit checks also suggests potential areas for further review.
In conclusion, while "mobile-wp-security" v1.2.0 benefits from a small attack surface and no known historical vulnerabilities, the static analysis reveals concerning practices regarding SQL query preparation and output escaping. The lack of fundamental security checks like nonces and capabilities is a significant weakness that should be addressed to ensure robust security against potential future threats.
Key Concerns
- SQL queries not using prepared statements
- Output escaping not properly handled
- Missing nonce checks
- Missing capability checks
Mobile WP Security Security Vulnerabilities
Mobile WP Security Code Analysis
SQL Query Safety
Output Escaping
Mobile WP Security Attack Surface
WordPress Hooks 15
Maintenance & Trust
Mobile WP Security Maintenance & Trust
Maintenance Signals
Community Trust
Mobile WP Security Alternatives
Nginx Mobile Theme
nginx-mobile-theme
This plugin allows you to switch theme according to the User Agent on the Nginx reverse proxy.
XMLRPC Lockdown by AO Digital
xmlrpc-lockdown
XMLRPC Lockdown by AO Digital is an advanced security plugin for WordPress. It blocks access to xmlrpc.php for all requests except those explicitly al …
AppsGeyser Plugin
appsgeyser-plug-in
AppsGeyser Plug-in for WordPress allows you to convert your blog into a native Android app. Make your blog easy to read on mobile devices.
cloudrebuesms
cloud-rebue-wpsms
Send Woocomerce Notifications, Access Bulk SMS Portal
Smartphone Location Lookup
smartphone-location-lookup
This plugins displays a location based map on your sidebar. It tells visitors to your blog exactly where YOU are!
Mobile WP Security Developer Profile
2 plugins · 30 total installs
How We Detect Mobile WP Security
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mobile-wp-security/includes/css/mobile-wp-security.css/wp-content/plugins/mobile-wp-security/includes/js/mobile-wp-security.js/wp-content/plugins/mobile-wp-security/includes/js/mobile-wp-security.jsmobile-wp-security/includes/css/mobile-wp-security.css?ver=mobile-wp-security/includes/js/mobile-wp-security.js?ver=HTML / DOM Fingerprints
mobile-wp-security-settings-pagemobile-wp-security plugin/wp-json/mobile-wp-security/v1/add-permanent-ban-ip/wp-json/mobile-wp-security/v1/remove-permanent-ban-ip/wp-json/mobile-wp-security/v1/add-temporary-ban-ip/wp-json/mobile-wp-security/v1/remove-temporary-ban-ip/wp-json/mobile-wp-security/v1/enable-ban/wp-json/mobile-wp-security/v1/get-ip-log/wp-json/mobile-wp-security/v1/website-data/wp-json/mobile-wp-security/v1/get-ip-rules/wp-json/mobile-wp-security/v1/get-ip-names/wp-json/mobile-wp-security/v1/set-ip-name/wp-json/mobile-wp-security/v1/remove-ip-name/wp-json/mobile-wp-security/v1/get-users/wp-json/mobile-wp-security/v1/get-roles/wp-json/mobile-wp-security/v1/create-user