Mockups Security & Risk Analysis

wordpress.org/plugins/mockups

Mockup Blocks for WordPress Gutenberg featuring 6 free iPhone X mockup photos.

10 active installs v1.0.2 PHP 7.2+ WP 5.1+ Updated Oct 5, 2019
devicesiphoneiphonexmockupsscreenshot
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Mockups Safe to Use in 2026?

Generally Safe

Score 85/100

Mockups has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The 'mockups' plugin v1.0.2 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by avoiding known dangerous functions, file operations, and external HTTP requests. The absence of any recorded vulnerabilities in its history is a strong indicator of a generally secure development process. Furthermore, the plugin does not bundle any external libraries, which eliminates the risk of relying on outdated or vulnerable third-party code. The attack surface is also remarkably small, with no AJAX handlers, REST API routes, shortcodes, or cron events, meaning there are very few potential entry points for attackers.

However, a significant concern arises from the complete lack of output escaping. With 10 total outputs and 0% properly escaped, this opens the door to Cross-Site Scripting (XSS) vulnerabilities. Any user-provided data that is displayed on the front-end without proper sanitization could be exploited. Additionally, the absence of nonce checks and capability checks on the identified entry points (even though there are none currently) is a potential weakness that could become a problem if the plugin evolves and new entry points are introduced without proper security measures. The taint analysis also shows no flows analyzed, which might indicate a lack of comprehensive security testing or a very simple plugin that inherently avoids taint issues.

In conclusion, while the 'mockups' plugin v1.0.2 benefits from a small attack surface and a clean vulnerability history, the critical issue of unescaped output poses a significant risk of XSS. The lack of security checks on potential future entry points also warrants attention. Developers should prioritize addressing the output escaping to improve the plugin's overall security.

Key Concerns

  • Unescaped output
  • No capability checks
  • No nonce checks
Vulnerabilities
None known

Mockups Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Mockups Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped10 total outputs
Attack Surface

Mockups Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionplugins_loadedblocks\iphonex\index.php:5
Maintenance & Trust

Mockups Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedOct 5, 2019
PHP min version7.2
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Mockups Developer Profile

launchui

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Mockups

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mockups/dist/assets/index-8f1e45e6.css/wp-content/plugins/mockups/dist/assets/index-45236511.js
Script Paths
/wp-content/plugins/mockups/dist/assets/index-45236511.js
Version Parameters
mockups/dist/assets/index-8f1e45e6.css?ver=mockups/dist/assets/index-45236511.js?ver=

HTML / DOM Fingerprints

CSS Classes
wp-block-mockups-device
Data Attributes
data-wp-block
JS Globals
wp
FAQ

Frequently Asked Questions about Mockups