
Pronto – Mobile Site Convertor Security & Risk Analysis
wordpress.org/plugins/obox-mobilePronto turns your WordPress website into a fully function mobile plugin.
Is Pronto – Mobile Site Convertor Safe to Use in 2026?
Generally Safe
Score 85/100Pronto – Mobile Site Convertor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "obox-mobile" v1.1.1 plugin presents a significant security risk primarily due to its extensive unprotected AJAX endpoints. While the plugin shows no known historical vulnerabilities (CVEs), this absence does not guarantee future safety and should not be interpreted as a sign of robust security. The static analysis reveals a concerning lack of authentication and authorization checks on all nine identified AJAX handlers. This means any unauthenticated user could potentially trigger these handlers, leading to unintended actions or information disclosure.
The code analysis also flags one SQL query that does not use prepared statements, which is a potential avenue for SQL injection if user input is involved in constructing that query. Furthermore, a very low percentage (7%) of output escaping indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the user interface.
Despite the absence of dangerous functions, file operations, external HTTP requests, and bundled libraries, the unprotected attack surface and poor output escaping are critical weaknesses. The taint analysis showing unsanitized paths, even without a critical severity rating, warrants attention as it indicates potential data flow issues that could be exploited in conjunction with other vulnerabilities.
Key Concerns
- All AJAX handlers lack authentication checks
- Low percentage of properly escaped output
- SQL query not using prepared statements
- Unsanitized paths in taint analysis
Pronto – Mobile Site Convertor Security Vulnerabilities
Pronto – Mobile Site Convertor Release Timeline
Pronto – Mobile Site Convertor Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Pronto – Mobile Site Convertor Attack Surface
AJAX Handlers 9
WordPress Hooks 36
Maintenance & Trust
Pronto – Mobile Site Convertor Maintenance & Trust
Maintenance Signals
Community Trust
Pronto – Mobile Site Convertor Alternatives
WPtouch – Make your WordPress Website Mobile-Friendly
wptouch
With just a few clicks, make your WordPress website mobile-friendly (iPhone, Android, and more). Recommended by Google, it will instantly enable a mob …
MOBILOOK — Mobile View & Mobile‑Friendly Test
mobilook
Instant mobile view of website (pages, posts, products) for responsive web design on phone (+ dualscreen). This plugin also offers helpful tools on ea …
AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker)
appmysite
Turn your WordPress or WooCommerce site into a native Android & iOS app in minutes — no coding required.
AppPresser – Mobile App Framework
apppresser
Connect your WordPress site to a native mobile app.
WP Mobile Redirect
mobile-redirect-plus-lite
Detect mobile device and redirect to mobile optimize website. You can also choose whether or not to redirect tablets by enabling or disabling the chec …
Pronto – Mobile Site Convertor Developer Profile
8 plugins · 2K total installs
How We Detect Pronto – Mobile Site Convertor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/obox-mobile/admin/js/ajaxupload.js/wp-content/plugins/obox-mobile/admin/js/admin.js/wp-content/plugins/obox-mobile/admin/js/upgrade.js/wp-content/plugins/obox-mobile/admin/css/style.css/wp-content/plugins/obox-mobile/admin/js/ajaxupload.js/wp-content/plugins/obox-mobile/admin/js/admin.js/wp-content/plugins/obox-mobile/admin/js/upgrade.jsobox-mobile/admin/css/style.css?v=1.0HTML / DOM Fingerprints
mobile-containermobile-title-blockobox-saveobox-resettabsselectedadmin-notebase-controls+1 more<!-- All the form buttons --><!-- OBOX Tabs --><!-- OBOX Form Content --><!-- Second row of form buttons -->id="mobile-options"name="mobile-options"id="mobile-note"id="header-block"id="tabs"class="tabs clearfix"+3 moreThemeAjaxobox_mobile_plugin_optionsobox_mobilewp-ajax.php