
NAPPS – Mobile app builder Security & Risk Analysis
wordpress.org/plugins/nappsCreate your app with NAPPS. We are a mobile app builder for e-commerce, download our plugin and start your free trial.
Is NAPPS – Mobile app builder Safe to Use in 2026?
Generally Safe
Score 92/100NAPPS – Mobile app builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "napps" plugin v1.0.27 exhibits a generally good security posture based on the provided static analysis. The plugin has a minimal attack surface, with only one REST API route, and critically, this route includes a permission callback, indicating proper access control for this entry point. The vast majority of outputs are properly escaped, and there are no critical or high-severity findings from taint analysis, nor any known vulnerabilities in its history. This suggests a developer who is mindful of common security practices.
However, a significant concern arises from the handling of SQL queries. Two SQL queries are present, and neither uses prepared statements. This lack of prepared statements makes the plugin susceptible to SQL injection vulnerabilities if user-supplied data is directly incorporated into these queries without proper sanitization, which is not explicitly demonstrated in the provided analysis. Additionally, the presence of a file operation and an external HTTP request, while not inherently problematic, warrants careful review to ensure they are handled securely and do not introduce unintended vulnerabilities.
While the plugin's vulnerability history is clean, the static analysis reveals areas for improvement. The absence of nonce checks and the presence of only one capability check across all entry points are minor weaknesses. The bundled Guzzle library, while a well-known HTTP client, should also be regularly updated to mitigate any potential vulnerabilities it might inherit. Overall, the plugin is in good shape, but the SQL query handling is a notable risk that needs immediate attention.
Key Concerns
- SQL queries without prepared statements
- Bundled library (Guzzle) potential for outdated version
- No nonce checks found
NAPPS – Mobile app builder Security Vulnerabilities
NAPPS – Mobile app builder Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
NAPPS – Mobile app builder Attack Surface
REST API Routes 1
WordPress Hooks 57
Maintenance & Trust
NAPPS – Mobile app builder Maintenance & Trust
Maintenance Signals
Community Trust
NAPPS – Mobile app builder Alternatives
WpApper – Create native mobile apps(Android and iOS)
wpapper
Create native app(Android & iOS). The wordpress plugin for Wpapper. CREATE NATIVE MOBILE APPS FOR YOUR WORDPRESS WEBSITES(Android and iOS)
WPMobile.App
wpappninja
Android and iOS mobile application. Easy setup, free test.
GoodBarber
goodbarber
GoodBarber plugin allows you to retrieve WordPress content in order to create a native app for iOS and/or Android
Device-Based Redirect
device-based-redirect
Redirect users to your app pages in app store or play store based on their device type with custom URLs and page-specific redirects.
Mobile Smart App Banner
mobile-smart-app-banner
Transform your mobile website visitors into app users with intelligent smart app banners that boost downloads across iOS and Android devices.
NAPPS – Mobile app builder Developer Profile
2 plugins · 10 total installs
How We Detect NAPPS – Mobile app builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/napps/public/css/napps.css/wp-content/plugins/napps/vendor/js/napps-frontend.js/wp-content/plugins/napps/vendor/js/napps-frontend.jsnapps/style.css?ver=napps-banner?ver=HTML / DOM Fingerprints
napps-getting-started-wrapperdata-napps-site-urlnapps_mobile_sdk_installed/wp-json/napps/v1/reset-password/wp-json/napps/v1/token