Pronto – Mobile Site Convertor Security & Risk Analysis

wordpress.org/plugins/obox-mobile

Pronto turns your WordPress website into a fully function mobile plugin.

100 active installs v1.1.1 PHP + WP 5.0.0+ Updated Mar 26, 2020
androidiphonemobileresponsiveslider
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Pronto – Mobile Site Convertor Safe to Use in 2026?

Generally Safe

Score 85/100

Pronto – Mobile Site Convertor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "obox-mobile" v1.1.1 plugin presents a significant security risk primarily due to its extensive unprotected AJAX endpoints. While the plugin shows no known historical vulnerabilities (CVEs), this absence does not guarantee future safety and should not be interpreted as a sign of robust security. The static analysis reveals a concerning lack of authentication and authorization checks on all nine identified AJAX handlers. This means any unauthenticated user could potentially trigger these handlers, leading to unintended actions or information disclosure.

The code analysis also flags one SQL query that does not use prepared statements, which is a potential avenue for SQL injection if user input is involved in constructing that query. Furthermore, a very low percentage (7%) of output escaping indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the user interface.

Despite the absence of dangerous functions, file operations, external HTTP requests, and bundled libraries, the unprotected attack surface and poor output escaping are critical weaknesses. The taint analysis showing unsanitized paths, even without a critical severity rating, warrants attention as it indicates potential data flow issues that could be exploited in conjunction with other vulnerabilities.

Key Concerns

  • All AJAX handlers lack authentication checks
  • Low percentage of properly escaped output
  • SQL query not using prepared statements
  • Unsanitized paths in taint analysis
Vulnerabilities
None known

Pronto – Mobile Site Convertor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Pronto – Mobile Site Convertor Release Timeline

v1.1.1Current
v1.1.0
v1.0.1
Code Analysis
Analyzed Mar 16, 2026

Pronto – Mobile Site Convertor Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
229
16 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

7% escaped245 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
obox_mobile_ajax_upload (admin\includes\media.php:3)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
9 unprotected

Pronto – Mobile Site Convertor Attack Surface

Entry Points9
Unprotected9

AJAX Handlers 9

authwp_ajax_validate_keyadmin\config\scripts.php:19
authwp_ajax_do_obox_mobile_upgradeadmin\config\scripts.php:20
authwp_ajax_obox_mobile_save-optionsadmin\config\scripts.php:21
authwp_ajax_obox_mobile_reset-optionsadmin\config\scripts.php:22
authwp_ajax_obox_mobile_ads-removeadmin\config\scripts.php:23
authwp_ajax_obox_mobile_ajax-uploadadmin\config\scripts.php:24
authwp_ajax_obox_mobile_theme-uploadadmin\config\scripts.php:25
authwp_ajax_obox_mobile_theme-removeadmin\config\scripts.php:26
authwp_ajax_obox_mobile_remove-imageadmin\config\scripts.php:27
WordPress Hooks 36
actionadmin_menuadmin\config\mobile-menus.php:42
actioninitadmin\config\navs-and-sidebars.php:64
actioninitadmin\config\options.php:1018
actioninitadmin\config\scripts.php:30
actionplugins_loadedadmin\includes\save-functions.php:166
actionobox_mobile_update_optionsadmin\includes\save-functions.php:167
actionobox_mobile_reset_optionadmin\includes\save-functions.php:168
actionobox_mobile_customization_formadmin\interface\customization.php:42
actionobox_mobile_form_optionsadmin\interface\general.php:18
filterstylesheetfunctions\class.php:221
filtertemplatefunctions\class.php:222
filtertheme_rootfunctions\class.php:223
filtertheme_root_urifunctions\class.php:224
filterget_the_excerptfunctions\class.php:226
filtershow_admin_barfunctions\class.php:228
actionwpfunctions\class.php:230
filtermobile_post_metafunctions\hooks.php:3
actionmobile_post_advertfunctions\hooks.php:4
actionmobile_author_biofunctions\hooks.php:5
filtermobile_author_biofunctions\hooks.php:6
actioninitfunctions\media.php:147
filterquery_varsfunctions\media.php:154
actiontemplate_redirectfunctions\media.php:163
filterwp_footerfunctions\mobi_switch.php:23
actionwp_print_stylesfunctions\mobi_switch.php:24
actioninitfunctions\mobi_switch.php:28
actionobox_mobile_social_linksfunctions\template.php:98
actionobox_mobile_post_metafunctions\template.php:145
actionobox_mobile_author_biofunctions\template.php:168
actionobox_mobile_sliderfunctions\template.php:185
actionwidgets_initfunctions\template.php:683
actionplugins_loadedmobile.php:38
actionplugins_loadedmobile.php:51
filterthe_contenttheme\functions.php:14
actionwp_enqueue_scriptstheme\inc\scripts.php:33
actionwp_enqueue_scriptstheme\inc\scripts.php:48
Maintenance & Trust

Pronto – Mobile Site Convertor Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedMar 26, 2020
PHP min version
Downloads6K

Community Trust

Rating74/100
Number of ratings3
Active installs100
Developer Profile

Pronto – Mobile Site Convertor Developer Profile

Julio Potier

8 plugins · 2K total installs

80
trust score
Avg Security Score
89/100
Avg Patch Time
52 days
View full developer profile
Detection Fingerprints

How We Detect Pronto – Mobile Site Convertor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/obox-mobile/admin/js/ajaxupload.js/wp-content/plugins/obox-mobile/admin/js/admin.js/wp-content/plugins/obox-mobile/admin/js/upgrade.js/wp-content/plugins/obox-mobile/admin/css/style.css
Script Paths
/wp-content/plugins/obox-mobile/admin/js/ajaxupload.js/wp-content/plugins/obox-mobile/admin/js/admin.js/wp-content/plugins/obox-mobile/admin/js/upgrade.js
Version Parameters
obox-mobile/admin/css/style.css?v=1.0

HTML / DOM Fingerprints

CSS Classes
mobile-containermobile-title-blockobox-saveobox-resettabsselectedadmin-notebase-controls+1 more
HTML Comments
<!-- All the form buttons --><!-- OBOX Tabs --><!-- OBOX Form Content --><!-- Second row of form buttons -->
Data Attributes
id="mobile-options"name="mobile-options"id="mobile-note"id="header-block"id="tabs"class="tabs clearfix"+3 more
JS Globals
ThemeAjaxobox_mobile_plugin_optionsobox_mobile
REST Endpoints
wp-ajax.php
FAQ

Frequently Asked Questions about Pronto – Mobile Site Convertor