Stionic Core – Create Mobile app for WordPress news Security & Risk Analysis

wordpress.org/plugins/stionic-core

Create mobile app for WordPress

100 active installs v1.0.28 PHP 5.2.4+ WP 4.7+ Updated Mar 27, 2022
apicreate-appmobile-app-wordpresswordpress-news-app
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Stionic Core – Create Mobile app for WordPress news Safe to Use in 2026?

Generally Safe

Score 85/100

Stionic Core – Create Mobile app for WordPress news has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "stionic-core" v1.0.28 plugin exhibits a generally strong security posture, with several key security mechanisms in place. The plugin demonstrates good practices by implementing nonce checks and capability checks, and its use of prepared statements for SQL queries is commendable, with a high percentage of queries utilizing them. Furthermore, the vast majority of output is properly escaped, and there are no recorded vulnerabilities in its history, which suggests a commitment to security and diligent development. The limited attack surface, consisting of a single AJAX handler without authentication checks, is a point of consideration, though the absence of any critical or high-severity taint flows is a positive sign.

While the plugin has a solid foundation, the presence of an unprotected AJAX handler, even if it's the only entry point in this category, warrants attention. Although no specific vulnerabilities were detected in static analysis or taint flows, and the vulnerability history is clean, the lack of an authentication check on the sole AJAX handler represents a potential entry point that could be exploited if the functionality within it is sensitive or can be abused. The plugin also makes external HTTP requests, which, while not inherently risky, can be a vector for certain types of attacks if the endpoints are not secured or if the data transmitted is not handled with care.

In conclusion, "stionic-core" v1.0.28 is a well-built plugin with robust internal security measures. Its clean vulnerability history and strong adherence to secure coding practices like prepared statements and output escaping are significant strengths. The primary area for improvement lies in ensuring that all AJAX handlers, even a single one, are protected with appropriate authentication and authorization checks to mitigate potential risks, especially considering it's the only identified entry point without such checks.

Key Concerns

  • AJAX handler without auth checks
Vulnerabilities
None known

Stionic Core – Create Mobile app for WordPress news Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Stionic Core – Create Mobile app for WordPress news Release Timeline

v1.0.28Current
v1.0.27
v1.0.26
v1.0.25
v1.0.24
v1.0.23
v1.0.22
v1.0.21
v1.0.20
v1.0.19
v1.0.18
v1.0.17
v1.0.16
v1.0.15
v1.0.14
v1.0.13
v1.0.12
v1.0.11
v1.0.10
v1.0.9
Code Analysis
Analyzed Mar 16, 2026

Stionic Core – Create Mobile app for WordPress news Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
2 prepared
Unescaped Output
8
177 escaped
Nonce Checks
6
Capability Checks
3
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

67% prepared3 total queries

Output Escaping

96% escaped185 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
save_taxonomy_order (admin\class-stionic-admin.php:223)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Stionic Core – Create Mobile app for WordPress news Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_update_taxonomy_orderadmin\class-stionic-admin.php:73
WordPress Hooks 22
filterrest_pre_dispatchadmin\class-stionic-admin.php:37
actionadmin_initadmin\class-stionic-admin.php:39
actionadmin_menuadmin\class-stionic-admin.php:41
actionwp_footeradmin\class-stionic-admin.php:43
filterrestrict_manage_postsadmin\class-stionic-list-posts.php:15
filterparse_queryadmin\class-stionic-list-posts.php:16
actionadd_meta_boxesadmin\class-stionic-metaboxes.php:8
actionsave_postadmin\class-stionic-metaboxes.php:9
actionpublish_future_postadmin\class-stionic-metaboxes.php:10
filterstionic_notification_filteradmin\class-stionic-metaboxes.php:11
actionrest_api_initendpoints\class-stionic-categories.php:8
actionrest_api_initendpoints\class-stionic-comments.php:8
filterrest_allow_anonymous_commentsendpoints\class-stionic-comments.php:10
actionrest_api_initendpoints\class-stionic-config.php:9
actionrest_api_initendpoints\class-stionic-pages.php:8
actionrest_api_initendpoints\class-stionic-posts.php:8
actionrest_api_initendpoints\class-stionic-tools.php:8
filterrest_prepare_posthooks\class-stionic-ads.php:9
filterrest_prepare_pagehooks\class-stionic-ads.php:10
actionrest_api_inithooks\class-stionic-header.php:8
filterrest_pre_serve_requesthooks\class-stionic-header.php:12
actionrest_api_initincludes\class-stionic-posts.php:8
Maintenance & Trust

Stionic Core – Create Mobile app for WordPress news Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedMar 27, 2022
PHP min version5.2.4
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Stionic Core – Create Mobile app for WordPress news Developer Profile

Noncheat

2 plugins · 130 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Stionic Core – Create Mobile app for WordPress news

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/stionic-core/admin/js/general.js
Script Paths
admin/js/general.js
Version Parameters
stionic-core/admin/js/general.js?v=

HTML / DOM Fingerprints

REST Endpoints
/wp/v2/m_config
FAQ

Frequently Asked Questions about Stionic Core – Create Mobile app for WordPress news