
RNWP App template config Security & Risk Analysis
wordpress.org/plugins/rnwp-app-template-configThis plugin adds search functionality through REST API over all enabled post types and adjust the maximum numbers of posts to fetch through the REST A …
Is RNWP App template config Safe to Use in 2026?
Generally Safe
Score 85/100RNWP App template config has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "rnwp-app-template-config" plugin, version 1.0.1, presents a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and implementing a good percentage of output escaping. There are no recorded vulnerabilities in its history, suggesting a generally stable codebase. However, a significant concern arises from its attack surface. The plugin exposes one REST API route without any permission callbacks, making it accessible to unauthenticated users. Furthermore, all 13 taint analysis flows analyzed involve unsanitized paths, which is a critical indicator of potential vulnerabilities, even though no specific high or critical severities were reported in the taint analysis itself. The presence of 13 unsanitized path flows is particularly worrying as it suggests that user-supplied input could potentially be used to manipulate file operations or access sensitive data, despite the lack of direct file operations or external HTTP requests reported.
While the plugin's vulnerability history is clean and it avoids common pitfalls like raw SQL queries and dangerous functions, the combination of an unprotected REST API endpoint and a high number of unsanitized path flows in taint analysis creates a substantial risk. The lack of authentication on a REST API endpoint means any user can interact with it, and if that interaction is not properly validated, it could lead to security issues. The 13 unsanitized path flows are a strong signal that input validation and sanitization are likely insufficient. A balanced conclusion would highlight the strengths in SQL handling and output escaping but emphasize the critical need to address the unprotected REST API and the pervasive unsanitized path flows before this plugin can be considered secure.
Key Concerns
- REST API route without permission callback
- 13 unsanitized path flows in taint analysis
RNWP App template config Security Vulnerabilities
RNWP App template config Code Analysis
Output Escaping
Data Flow Analysis
RNWP App template config Attack Surface
REST API Routes 1
WordPress Hooks 8
Maintenance & Trust
RNWP App template config Maintenance & Trust
Maintenance Signals
Community Trust
RNWP App template config Alternatives
WPMobile.App
wpappninja
Android and iOS mobile application. Easy setup, free test.
Mobile Smart App Banner
mobile-smart-app-banner
Transform your mobile website visitors into app users with intelligent smart app banners that boost downloads across iOS and Android devices.
WP-AppKit – Mobile apps and PWA for WordPress
wp-appkit
Important ✋: beginning with version 1.5.3, we don't support anymore native iOS app. This is a tough choice we explain here.
IdeaPress – Turn WordPress into Mobile Apps (Android, iPhone, WinPhone)
ideapress-json-api
Don't write a single line of code. Turn your wordpress into mobile app in 5 mins. (Android, iOS, winPhone)
APPExperts – Mobile App Builder for WordPress | WooCommerce to iOS and Android Apps
appexperts
APPExperts is a freemium mobile app builder that gives you the power to turn your WordPress-powered website into a mobile application for iOS and Andr …
RNWP App template config Developer Profile
2 plugins · 20 total installs
How We Detect RNWP App template config
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rnwp-app-template-config/css/w3.css/wp-content/plugins/rnwp-app-template-config/css/style.css/wp-content/plugins/rnwp-app-template-config/js/custom.jsrnwp-app-template-config/css/w3.css?ver=rnwp-app-template-config/css/style.css?ver=rnwp-app-template-config/js/custom.js?ver=HTML / DOM Fingerprints
/wp-json/wp/v2/product_cat/wp-json/wp/v2/product_tag