
Smart PWA Installer Security & Risk Analysis
wordpress.org/plugins/smart-pwa-installerSmart PWA Installer adds PWA support to your site with a floating install button and logs.
Is Smart PWA Installer Safe to Use in 2026?
Generally Safe
Score 100/100Smart PWA Installer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The smart-pwa-installer plugin v1.2.0 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, external HTTP requests, and the consistent use of prepared statements for SQL queries are positive indicators. Furthermore, the excellent output escaping rate (88%) and the presence of a nonce check are commendable security practices. The limited attack surface, with all entry points protected by authentication, further bolsters confidence.
However, a key area of concern is the complete lack of capability checks. While AJAX handlers are protected by authentication, not verifying user capabilities could allow authenticated users with lower privileges to perform actions they shouldn't be able to, potentially leading to privilege escalation or unauthorized access to sensitive functionalities. The taint analysis showing zero flows, while seemingly positive, could also indicate insufficient or incomplete taint analysis, rather than a complete absence of vulnerabilities.
The plugin's vulnerability history is also a positive sign, with no recorded CVEs. This suggests a history of responsible development and a lack of previously identified exploitable flaws. However, the absence of past vulnerabilities does not guarantee future security, and the lack of capability checks remains a significant oversight that should be addressed.
Key Concerns
- Missing capability checks on entry points
Smart PWA Installer Security Vulnerabilities
Smart PWA Installer Code Analysis
SQL Query Safety
Output Escaping
Smart PWA Installer Attack Surface
AJAX Handlers 2
WordPress Hooks 6
Maintenance & Trust
Smart PWA Installer Maintenance & Trust
Maintenance Signals
Community Trust
Smart PWA Installer Alternatives
CodeQuill Web to App
codequill-web-to-app
Convert your WordPress site into a Progressive Web App (PWA). Add an Install App button and manage settings directly from the dashboard.
Super Progressive Web Apps
super-progressive-web-apps
SuperPWA helps you convert your WordPress website into a Progressive Web App instantly.
PWA
pwa
WordPress feature plugin to bring Progressive Web App (PWA) capabilities to Core
PWA for WP – Progressive Web Apps Made Simple
pwa-for-wp
PWA plugin is bringing the power of the Progressive Web Apps to the WP & AMP to take the user experience to the next level.
PWA — easy way to Progressive Web App
iworks-pwa
Your easy way to Progressive Web Application.
Smart PWA Installer Developer Profile
1 plugin · 0 total installs
How We Detect Smart PWA Installer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smart-pwa-installer/assets/smrpwa-admin.css/wp-content/plugins/smart-pwa-installer/assets/smrpwa-frontend.css/wp-content/plugins/smart-pwa-installer/assets/install.js/wp-content/plugins/smart-pwa-installer/assets/install.jssmart-pwa-installer/assets/smrpwa-admin.css?ver=smart-pwa-installer/assets/smrpwa-frontend.css?ver=smart-pwa-installer/assets/install.js?ver=HTML / DOM Fingerprints
smrpwa-install-btnid="smrpwa-install-btn"smrpwa