Mobile Detect Security & Risk Analysis

wordpress.org/plugins/tinywp-mobile-detect

Fine-tunes wp_is_mobile function by excluding tablets (ex: iPad), from being detected as mobile! Uses MobileDetect PHP Library from mobiledetect.net!

3K active installs v3.1.1 PHP 7.4+ WP 3.0+ Updated Mar 6, 2026
browsersipadmobilemobiledetecttablet
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Mobile Detect Safe to Use in 2026?

Generally Safe

Score 100/100

Mobile Detect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 28d ago
Risk Assessment

The "tinywp-mobile-detect" v3.1.1 plugin exhibits a very strong security posture based on the provided static analysis. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code signals are all positive, indicating no dangerous functions, all SQL queries use prepared statements, and all output is properly escaped. The lack of file operations, external HTTP requests, nonce checks, capability checks, and bundled libraries further solidifies this good security practice.

The vulnerability history also shows no recorded CVEs, which suggests a history of responsible development and patching, or a lack of past exploitation. The taint analysis reveals no flows with unsanitized paths, indicating no critical or high-severity issues related to data manipulation. Overall, the plugin appears to be exceptionally well-secured, with no immediate exploitable vulnerabilities identified through this analysis. However, the very limited functionality and attack surface might be a contributing factor to the lack of identified issues, and a lack of any checks (like nonces or capabilities) might not be a concern if there are no entry points to protect.

Vulnerabilities
None known

Mobile Detect Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Mobile Detect Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Mobile Detect Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filterwp_is_mobilemobile-detect.php:29
filterwp_is_mobilemobile-detect.php:31
Maintenance & Trust

Mobile Detect Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 6, 2026
PHP min version7.4
Downloads47K

Community Trust

Rating100/100
Number of ratings7
Active installs3K
Developer Profile

Mobile Detect Developer Profile

Pothi Kalimuthu

3 plugins · 3K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Mobile Detect

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tinywp-mobile-detect/inc/TinyWP_MobileDetect.php
Version Parameters
tinywp-mobile-detect/inc/TinyWP_MobileDetect.php?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Mobile Detect