
Mockups Security & Risk Analysis
wordpress.org/plugins/mockupsMockup Blocks for WordPress Gutenberg featuring 6 free iPhone X mockup photos.
Is Mockups Safe to Use in 2026?
Generally Safe
Score 85/100Mockups has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'mockups' plugin v1.0.2 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by avoiding known dangerous functions, file operations, and external HTTP requests. The absence of any recorded vulnerabilities in its history is a strong indicator of a generally secure development process. Furthermore, the plugin does not bundle any external libraries, which eliminates the risk of relying on outdated or vulnerable third-party code. The attack surface is also remarkably small, with no AJAX handlers, REST API routes, shortcodes, or cron events, meaning there are very few potential entry points for attackers.
However, a significant concern arises from the complete lack of output escaping. With 10 total outputs and 0% properly escaped, this opens the door to Cross-Site Scripting (XSS) vulnerabilities. Any user-provided data that is displayed on the front-end without proper sanitization could be exploited. Additionally, the absence of nonce checks and capability checks on the identified entry points (even though there are none currently) is a potential weakness that could become a problem if the plugin evolves and new entry points are introduced without proper security measures. The taint analysis also shows no flows analyzed, which might indicate a lack of comprehensive security testing or a very simple plugin that inherently avoids taint issues.
In conclusion, while the 'mockups' plugin v1.0.2 benefits from a small attack surface and a clean vulnerability history, the critical issue of unescaped output poses a significant risk of XSS. The lack of security checks on potential future entry points also warrants attention. Developers should prioritize addressing the output escaping to improve the plugin's overall security.
Key Concerns
- Unescaped output
- No capability checks
- No nonce checks
Mockups Security Vulnerabilities
Mockups Code Analysis
Output Escaping
Mockups Attack Surface
WordPress Hooks 1
Maintenance & Trust
Mockups Maintenance & Trust
Maintenance Signals
Community Trust
Mockups Alternatives
Devices for Elementor
devices-elementor
Devices for Elementor is a powerful Elementor widget that lets you add a phone, tablet, laptop, desktop or window / browser frame to your images or sc …
iPhone Control Panel
iphone-control-panel
Configure how iPhones and iPod touches see your site. Add custom css, a home screen bookmark icon, change the viewport, or redirect to another url.
Favicon by RealFaviconGenerator
favicon-by-realfavicongenerator
Create and install your favicon for all platforms: PC/Mac, iPhone/iPad, Android devices, Windows 8 tablets...
WPtouch – Make your WordPress Website Mobile-Friendly
wptouch
With just a few clicks, make your WordPress website mobile-friendly (iPhone, Android, and more). Recommended by Google, it will instantly enable a mob …
Multi Device Switcher
multi-device-switcher
Multi Device Switcher plugin allows you to set a separate theme for device (Smart Phone, Tablet PC, Mobile Phone, Game and custom).
Mockups Developer Profile
1 plugin · 10 total installs
How We Detect Mockups
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mockups/dist/assets/index-8f1e45e6.css/wp-content/plugins/mockups/dist/assets/index-45236511.js/wp-content/plugins/mockups/dist/assets/index-45236511.jsmockups/dist/assets/index-8f1e45e6.css?ver=mockups/dist/assets/index-45236511.js?ver=HTML / DOM Fingerprints
wp-block-mockups-devicedata-wp-blockwp