
MobStac WordPress Mobile Security & Risk Analysis
wordpress.org/plugins/mobstac-bloggerRenders for mobile visitors a mobile version of your WordPress site, with blazing-fast page loads, multiple themes, support for over 5000 mobile devi …
Is MobStac WordPress Mobile Safe to Use in 2026?
Generally Safe
Score 85/100MobStac WordPress Mobile has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mobstac-blogger" v2.75 plugin exhibits a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities (CVEs) and demonstrates good practices in database interactions, with 100% of SQL queries using prepared statements. Furthermore, the attack surface appears minimal, with zero identified AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, none of these potential entry points are reported as unprotected.
However, significant concerns arise from the static code analysis. The presence of dangerous functions like `preg_replace(/e)` and `create_function` indicates potential for arbitrary code execution if user-supplied data can influence their behavior. The low rate of proper output escaping (9%) is a notable weakness, increasing the risk of cross-site scripting (XSS) vulnerabilities. The taint analysis reveals a high number of flows with unsanitized paths (6 out of 7 analyzed), which, while not resulting in critical or high severity issues in this specific analysis, points to a systemic lack of input validation and sanitization. The absence of nonce checks is another critical oversight, leaving any potential AJAX endpoints vulnerable to CSRF attacks if they were to exist or be introduced in the future. The plugin also performs file operations and external HTTP requests, which, without proper validation and sanitization on the input controlling these actions, could lead to further security issues.
Given the lack of historical vulnerabilities, it's possible these code-level risks haven't been exploited or are mitigated by other factors not visible in this analysis. However, the identified code signals and taint analysis results present clear, actionable security concerns that significantly detract from the plugin's overall security. The developer should prioritize addressing these issues to improve the plugin's robustness and security.
Key Concerns
- Dangerous functions used (preg_replace(/e), create_function)
- Low rate of properly escaped output (9%)
- High number of flows with unsanitized paths
- No nonce checks present
- Only 1 capability check for 1 entry point
MobStac WordPress Mobile Security Vulnerabilities
MobStac WordPress Mobile Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
MobStac WordPress Mobile Attack Surface
WordPress Hooks 8
Maintenance & Trust
MobStac WordPress Mobile Maintenance & Trust
Maintenance Signals
Community Trust
MobStac WordPress Mobile Alternatives
WPtouch – Make your WordPress Website Mobile-Friendly
wptouch
With just a few clicks, make your WordPress website mobile-friendly (iPhone, Android, and more). Recommended by Google, it will instantly enable a mob …
AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker)
appmysite
Turn your WordPress or WooCommerce site into a native Android & iOS app in minutes — no coding required.
AppPresser – Mobile App Framework
apppresser
Connect your WordPress site to a native mobile app.
MOBILOOK — Mobile View & Mobile‑Friendly Test
mobilook
Instant mobile view of website (pages, posts, products) for responsive web design on phone (+ dualscreen). This plugin also offers helpful tools on ea …
WP Mobile Redirect
mobile-redirect-plus-lite
Detect mobile device and redirect to mobile optimize website. You can also choose whether or not to redirect tablets by enabling or disabling the chec …
MobStac WordPress Mobile Developer Profile
1 plugin · 10 total installs
How We Detect MobStac WordPress Mobile
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mobstac-blogger/js/mobstac-tracking.js/wp-content/plugins/mobstac-blogger/css/mobstac-styling.css/wp-content/plugins/mobstac-blogger/js/mobstac-tracking.jsmobstac-blogger/js/mobstac-tracking.js?ver=mobstac-blogger/css/mobstac-styling.css?ver=HTML / DOM Fingerprints
<!-- MobStac Wordpress --><!-- Mobstac Wordpress plugin by MobStac --><!-- Mobstac Wordpress Plugin -->data-mobstac-idwindow.mobstac_tracker_infovar mobstac_redirect_urlvar mobstac_api_key