MobiLoud – Smart App Banners Security & Risk Analysis

wordpress.org/plugins/mobiloud-smart-app-banner

We created this plugin so that you can use Smart App Banners on your WordPress site to boost downloads for your iOS and Android app.

200 active installs v1.1.3 PHP + WP 3.5+ Updated Jan 29, 2021
applicationmobilemobile-appnative-appsmart-app-banners
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MobiLoud – Smart App Banners Safe to Use in 2026?

Generally Safe

Score 85/100

MobiLoud – Smart App Banners has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The static analysis of "mobiloud-smart-app-banner" v1.1.3 reveals a generally good security posture with no identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events. The plugin also shows positive signs in its code signals, with no dangerous functions, all SQL queries utilizing prepared statements, and no file operations or external HTTP requests. However, a significant concern arises from the output escaping, where only 53% of the 17 total outputs are properly escaped. This indicates a potential for cross-site scripting (XSS) vulnerabilities if unsanitized data is directly outputted to the browser. The taint analysis also found no flows, which is positive, but the lack of detailed flows analyzed might mean deeper issues were not detected.

The plugin's vulnerability history is clean, with zero known CVEs and no recorded vulnerabilities. This suggests that in its past iterations, the plugin has been relatively secure or any found issues were promptly addressed and patched. This lack of historical vulnerabilities is a strong positive indicator of responsible development and maintenance. Despite the clean history, the identified weakness in output escaping warrants attention. While the absence of a large attack surface and dangerous functions is commendable, the 53% output escaping rate is a notable security gap that could be exploited.

In conclusion, "mobiloud-smart-app-banner" v1.1.3 exhibits strengths in its minimal attack surface, secure database interactions, and lack of historical vulnerabilities. However, the substantial portion of unescaped output presents a tangible risk that needs to be addressed. The plugin is generally secure in its foundational aspects, but this specific area of output handling could be a vector for attacks. Developers should prioritize improving the output escaping mechanisms to mitigate potential XSS threats.

Key Concerns

  • Poor output escaping
Vulnerabilities
None known

MobiLoud – Smart App Banners Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

MobiLoud – Smart App Banners Release Timeline

v1.1.3Current
v1.1.2
v1.1.1
v1.1.0
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

MobiLoud – Smart App Banners Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

53% escaped17 total outputs
Attack Surface

MobiLoud – Smart App Banners Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_initadmin\class-msab-admin.php:28
actionadmin_menuadmin\class-msab-admin.php:29
actionadmin_enqueue_scriptsadmin\class-msab-admin.php:31
actionwp_headincludes\class-msab.php:25
actionwp_footerincludes\class-msab.php:26
actionwp_enqueue_scriptsincludes\class-msab.php:27
Maintenance & Trust

MobiLoud – Smart App Banners Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedJan 29, 2021
PHP min version
Downloads6K

Community Trust

Rating80/100
Number of ratings2
Active installs200
Developer Profile

MobiLoud – Smart App Banners Developer Profile

pietro

2 plugins · 500 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect MobiLoud – Smart App Banners

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mobiloud-smart-app-banner/admin/js/custom.js

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about MobiLoud – Smart App Banners