MoFuse WordPress Plugin Security & Risk Analysis

wordpress.org/plugins/mofuse

Requires at least 2.0.2 Test up to: 2.7.1 Stable tag: 2.7.1 This plugin works with a MoFuse account. This plugin will automatically detect and redir …

10 active installs v0.9o PHP + WP + Updated Jan 26, 2010
cellphonemobilemobilephonemofusexhtml
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MoFuse WordPress Plugin Safe to Use in 2026?

Generally Safe

Score 85/100

MoFuse WordPress Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 16yr ago
Risk Assessment

The "mofuse" plugin v0.9o exhibits a mixed security posture. On the positive side, the static analysis reveals no identifiable attack surface through common entry points like AJAX handlers, REST API, shortcodes, or cron events. Furthermore, the plugin does not utilize any dangerous functions, all SQL queries are properly prepared, and there are no file operations or external HTTP requests, which significantly reduces the potential for many common attack vectors. The absence of recorded vulnerabilities also suggests a history of stable security.

However, a critical concern arises from the taint analysis, which indicates three flows with unsanitized paths. While no critical or high severity vulnerabilities were identified in the taint analysis, the presence of unsanitized paths is a direct indicator of potential weaknesses that could be exploited. Compounding this is the fact that 0% of the 10 total output operations are properly escaped. This lack of output escaping creates a significant risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the content displayed to users.

In conclusion, while "mofuse" v0.9o demonstrates good practices in minimizing its attack surface and employing secure database interactions, the findings of unsanitized paths in taint analysis and widespread unescaped output represent substantial security weaknesses. These issues, if not addressed, could lead to serious security breaches, particularly XSS attacks. The lack of historical vulnerabilities is a positive sign, but it does not negate the present risks identified in the code.

Key Concerns

  • Unsanitized paths found in taint analysis
  • No output properly escaped
Vulnerabilities
None known

MoFuse WordPress Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

MoFuse WordPress Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped10 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
wp_mf_mobile_detect (mofuse.php:27)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

MoFuse WordPress Plugin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioninitmofuse.php:144
actionadmin_menumofuse.php:145
Maintenance & Trust

MoFuse WordPress Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedJan 26, 2010
PHP min version
Downloads10K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

MoFuse WordPress Plugin Developer Profile

dberube

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MoFuse WordPress Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
mofuse_wrapmofuse_logomofuse_yellow_messagemofuse_linksmofuse_links_leftmofuse_links_rightmofuse_settings_boxmofuse_headline+6 more
Data Attributes
id="mofuse_wrap"id="mofuse_logo"id="mofuse_yellow_message"id="mofuse_links"id="mofuse_links_left"id="mofuse_links_right"+3 more
FAQ

Frequently Asked Questions about MoFuse WordPress Plugin