
prograpper Security & Risk Analysis
wordpress.org/plugins/prograpperCreate (android / ios ) App for your WordPress Site
Is prograpper Safe to Use in 2026?
Generally Safe
Score 85/100prograpper has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "prograpper" v0.0.6 plugin exhibits a generally good security posture based on the provided static analysis. The absence of any identified dangerous functions, file operations, or external HTTP requests is a positive indicator. Furthermore, all SQL queries are prepared, and there are a reasonable number of capability checks and a single nonce check, suggesting an awareness of common WordPress security practices for controlling access and user actions. The plugin also boasts zero known vulnerabilities, both historically and currently, which is an excellent sign of its stability and security.
However, a significant concern arises from the low percentage of properly escaped output (25%). This indicates that a substantial portion of user-generated or dynamic content might be rendered to the browser without adequate sanitization, creating a potential for Cross-Site Scripting (XSS) vulnerabilities. While the static analysis did not reveal any taint flows or direct indications of XSS, the lack of output escaping presents a substantial risk that could be exploited if the plugin handles user-provided data that is subsequently displayed.
In conclusion, while the plugin demonstrates strengths in its controlled SQL usage, limited attack surface, and lack of historical vulnerabilities, the poor output escaping practices are a critical weakness. Addressing the output escaping for all dynamic content should be the immediate priority to mitigate the risk of XSS attacks. The absence of any identified XSS in the taint analysis is reassuring but doesn't negate the inherent risk posed by unescaped output.
Key Concerns
- Low output escaping percentage
prograpper Security Vulnerabilities
prograpper Release Timeline
prograpper Code Analysis
Output Escaping
prograpper Attack Surface
WordPress Hooks 45
Maintenance & Trust
prograpper Maintenance & Trust
Maintenance Signals
Community Trust
prograpper Alternatives
Reactor: Core
reactor-core
Reactor: Core connects your site to mobile apps built with Reactor: Builder. Adds JSON API endpoints to allow custom data in your Reactor powered apps …
WPMobile.App
wpappninja
Android and iOS mobile application. Easy setup, free test.
AppPresser – Mobile App Framework
apppresser
Connect your WordPress site to a native mobile app.
Mobile Smart App Banner
mobile-smart-app-banner
Transform your mobile website visitors into app users with intelligent smart app banners that boost downloads across iOS and Android devices.
APPExperts – Mobile App Builder for WordPress | WooCommerce to iOS and Android Apps
appexperts
APPExperts is a freemium mobile app builder that gives you the power to turn your WordPress-powered website into a mobile application for iOS and Andr …
prograpper Developer Profile
1 plugin · 10 total installs
How We Detect prograpper
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/prograpper/admin/css/prograpper-admin.css/wp-content/plugins/prograpper/admin/js/prograpper-admin.js/wp-content/plugins/prograpper/admin/js/prograpper-admin.jsprograpper-admin.css?ver=prograpper-admin.js?ver=