
PHP Mobile Redirect Security & Risk Analysis
wordpress.org/plugins/php-mobile-redirectEasily detect mobile devices and redirect them to the mobile version of your site.
Is PHP Mobile Redirect Safe to Use in 2026?
Generally Safe
Score 85/100PHP Mobile Redirect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "php-mobile-redirect" plugin v1.4 exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points suggests a minimal attack surface. Furthermore, the code signals indicate a lack of dangerous functions, secure SQL query practices, and no file operations or external HTTP requests, all of which are positive security indicators. The taint analysis also reveals no critical or high severity unsanitized flows.
However, a significant concern arises from the output escaping. With 3 total outputs and 0% properly escaped, this indicates a potential for Cross-Site Scripting (XSS) vulnerabilities. While the vulnerability history is clean, the lack of robust output escaping is a glaring weakness that could be exploited if any user-provided data is ever incorporated into the plugin's output in the future. The absence of nonce and capability checks, while not directly exploitable given the current attack surface, represents missed opportunities for defensive coding practices that could mitigate future risks if the plugin's functionality were to evolve.
In conclusion, while the plugin's current design minimizes direct exploitable attack vectors and demonstrates good practices in areas like SQL querying, the critical flaw in output escaping presents a notable risk. The clean vulnerability history is reassuring but should not overshadow the immediate need to address the unescaped output.
Key Concerns
- Outputs are not properly escaped
- Missing nonce checks
- Missing capability checks
PHP Mobile Redirect Security Vulnerabilities
PHP Mobile Redirect Release Timeline
PHP Mobile Redirect Code Analysis
Output Escaping
PHP Mobile Redirect Attack Surface
WordPress Hooks 3
Maintenance & Trust
PHP Mobile Redirect Maintenance & Trust
Maintenance Signals
Community Trust
PHP Mobile Redirect Alternatives
Average Mobile Detect
average-mobile-detect
Redirects mobile traffic to mobile site, allows visitors to opt for desktop site, provides shortcodes and widget to generate links to mobile site
Equivalent Mobile Redirect
equivalent-mobile-redirect
Easy way to detect and redirect mobile visitors to the equivalent page on your mobile site. Optionally redirect all mobile users to one mobile URL.
mobile detection
wordpress-mobile-detection
Detect mobile visitors to a wordpress based website and automatic activate the specific mobile theme.
Any Mobile Theme Switcher
any-mobile-theme-switcher
This Plugin detects mobile browser and display the theme as the setting done from admin. Usefull for switch to Mobile Theme.
Conditional Display for Mobile – Mobile Detect Plugin
wonderplugin-conditional-display
Conditional Display for Mobile can be used to control what content is displayed depending on the visitor's device or web browser.
PHP Mobile Redirect Developer Profile
2 plugins · 2K total installs
How We Detect PHP Mobile Redirect
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/php-mobile-redirect/css/pmr_style.css/wp-content/plugins/php-mobile-redirect/js/pmr_script.js/wp-content/plugins/php-mobile-redirect/js/pmr_script.jsphp-mobile-redirect/css/pmr_style.css?ver=php-mobile-redirect/js/pmr_script.js?ver=