
Reactor: Core Security & Risk Analysis
wordpress.org/plugins/reactor-coreReactor: Core connects your site to mobile apps built with Reactor: Builder. Adds JSON API endpoints to allow custom data in your Reactor powered apps …
Is Reactor: Core Safe to Use in 2026?
Generally Safe
Score 85/100Reactor: Core has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The reactor-core plugin version 0.2.5 exhibits a concerning security posture, primarily due to its significant attack surface exposed through unprotected AJAX handlers. While the plugin demonstrates good practices in other areas, such as the complete use of prepared statements for SQL queries and a lack of recorded vulnerabilities, the four unprotected AJAX entry points represent a substantial risk. The presence of the `unserialize` function, coupled with one unsanitized taint flow, further amplifies this concern, as these could be leveraged to achieve remote code execution or other severe impacts if an attacker can control the serialized data.
The plugin's vulnerability history is a positive indicator, showing no known CVEs and no past vulnerabilities. This suggests a generally stable codebase or perhaps limited public scrutiny. However, the static analysis reveals clear weaknesses that could potentially lead to future vulnerabilities. The high percentage of properly escaped outputs is a strength, as is the presence of nonce and capability checks on some entry points. Nevertheless, the core issue of unprotected AJAX handlers and the potential for insecure unserialization remain the most critical areas of concern, outweighing the positive aspects of its vulnerability-free history and secure SQL practices.
Key Concerns
- Unprotected AJAX handlers
- Dangerous function: unserialize
- Taint flow with unsanitized paths
- Low output escaping coverage
Reactor: Core Security Vulnerabilities
Reactor: Core Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Reactor: Core Attack Surface
AJAX Handlers 4
WordPress Hooks 55
Maintenance & Trust
Reactor: Core Maintenance & Trust
Maintenance Signals
Community Trust
Reactor: Core Alternatives
WPMobile.App
wpappninja
Android and iOS mobile application. Easy setup, free test.
AppPresser – Mobile App Framework
apppresser
Connect your WordPress site to a native mobile app.
Mobile Smart App Banner
mobile-smart-app-banner
Transform your mobile website visitors into app users with intelligent smart app banners that boost downloads across iOS and Android devices.
APPExperts – Mobile App Builder for WordPress | WooCommerce to iOS and Android Apps
appexperts
APPExperts is a freemium mobile app builder that gives you the power to turn your WordPress-powered website into a mobile application for iOS and Andr …
Knowband Mobile App Builder
knowband-mobile-app-builder-for-woocommerce
The Knowband Mobile App Builder converts your online store into a pair of native Android & iOS apps without any coding.
Reactor: Core Developer Profile
9 plugins · 1.0M total installs
How We Detect Reactor: Core
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
JSON_REQUEST/wp-json/