PWA+AMP Security & Risk Analysis

wordpress.org/plugins/pwamp

Converts WordPress into Progressive Web Apps and Accelerated Mobile Pages styles.

10 active installs v5.10.0 PHP 5.2.4+ WP 4.7+ Updated Jan 15, 2021
accelerated-mobile-pagesampgooglepwatheme
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PWA+AMP Safe to Use in 2026?

Generally Safe

Score 85/100

PWA+AMP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The plugin "pwamp" v5.10.0 presents a surprisingly low-risk profile based on the provided static analysis and vulnerability history. The absence of any detected entry points like AJAX handlers, REST API routes, shortcodes, or cron events is a significant strength, as it drastically limits the plugin's attack surface. Furthermore, the code analysis indicates a lack of dangerous functions, file operations, external HTTP requests, and bundled libraries, all of which contribute to a more secure codebase. The use of prepared statements for all SQL queries is a critical security best practice that has been followed diligently.

Key Concerns

  • Unescaped output detected
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

PWA+AMP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

PWA+AMP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped5 total outputs
Attack Surface

PWA+AMP Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionafter_setup_themepwamp.php:667
actionshutdownpwamp.php:668
actionwp_headpwamp.php:690
actionwp_headpwamp.php:691
actionwp_footerpwamp.php:693
actionwp_footerpwamp.php:694
actionafter_setup_themepwamp.php:696
actionshutdownpwamp.php:697
filtercomment_post_redirectpwamp.php:699
filterwp_die_json_handlerpwamp.php:700
filtershow_admin_barpwamp.php:702
actionplugins_loadedpwamp.php:715
Maintenance & Trust

PWA+AMP Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedJan 15, 2021
PHP min version5.2.4
Downloads6K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

PWA+AMP Developer Profile

rickey29

3 plugins · 310 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PWA+AMP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pwamp/pwamp/manifest/mf-logo-192.png/wp-content/plugins/pwamp/pwamp/manifest/mf-logo-512.png/wp-content/plugins/pwamp/pwamp/serviceworker/sw-toolbox.js
Script Paths
/wp-content/plugins/pwamp/pwamp/serviceworker/sw-toolbox.js

HTML / DOM Fingerprints

JS Globals
swsource
FAQ

Frequently Asked Questions about PWA+AMP