webtoapp.design – Convert Your WordPress Website to an App and Send Push Notifications Security & Risk Analysis

wordpress.org/plugins/webtoapp-design

✅ Convert Website to App ✅ Android & iOS ✅ Automatically Shows Website Changes ✅ Publish in App Stores ✅ Send Push Notifications with this Plugin ✅

10 active installs v1.0.3 PHP 7.2+ WP 5.8+ Updated Sep 3, 2024
android-appapp-buildercreate-appios-appwebsite-to-app-converter
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is webtoapp.design – Convert Your WordPress Website to an App and Send Push Notifications Safe to Use in 2026?

Generally Safe

Score 92/100

webtoapp.design – Convert Your WordPress Website to an App and Send Push Notifications has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The webtoapp-design plugin v1.0.3 exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates good practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and properly escaping a high percentage of its output. The absence of known vulnerabilities in its history and a lack of critical or high severity issues in taint analysis further contribute to this positive assessment. The limited attack surface, with no apparent AJAX handlers, REST API routes, shortcodes, or cron events, also reduces the potential for exploitation.

However, there are a couple of areas that warrant attention. The presence of two taint flows with unsanitized paths, despite not being classified as critical or high severity, indicates a potential for issues if the data involved is user-controlled and used in sensitive operations. Additionally, while only one external HTTP request is present, the security implications of this request should be carefully reviewed. The single nonce check suggests that some level of security measure is in place, but a complete absence of capability checks on the attack surface is a notable weakness, implying that actions might be accessible without proper user authorization if an entry point were discovered.

Overall, webtoapp-design v1.0.3 appears to be a relatively secure plugin, with its strengths lying in its well-controlled code execution and output handling. The identified taint flows and the lack of capability checks are the primary areas to monitor for potential future vulnerabilities. Continued vigilance and code review are recommended, especially concerning the unsanitized paths and the handling of the external HTTP request.

Key Concerns

  • Taint flows with unsanitized paths detected
  • External HTTP request present, needs review
  • No capability checks on identified entry points
Vulnerabilities
None known

webtoapp.design – Convert Your WordPress Website to an App and Send Push Notifications Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

webtoapp.design – Convert Your WordPress Website to an App and Send Push Notifications Release Timeline

v1.0.4
v1.0.3Current
v1.0.2
v1.0.1
Code Analysis
Analyzed Mar 16, 2026

webtoapp.design – Convert Your WordPress Website to an App and Send Push Notifications Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
28 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

93% escaped30 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
options_page_echo (webtoapp_options.php:250)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

webtoapp.design – Convert Your WordPress Website to an App and Send Push Notifications Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_enqueue_scriptsmedia.php:13
filterwp_fatal_error_handler_enabledwebtoapp.php:23
actiontransition_post_statuswebtoapp.php:27
actionplugins_loadedwebtoapp.php:29
actionshutdownwebtoapp.php:45
actionadmin_menuwebtoapp_options.php:33
actionadmin_initwebtoapp_options.php:35
actionadmin_enqueue_scriptswebtoapp_options.php:37
Maintenance & Trust

webtoapp.design – Convert Your WordPress Website to an App and Send Push Notifications Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedSep 3, 2024
PHP min version7.2
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

webtoapp.design – Convert Your WordPress Website to an App and Send Push Notifications Developer Profile

webtoappdesign

1 plugin · 10 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect webtoapp.design – Convert Your WordPress Website to an App and Send Push Notifications

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/webtoapp-design/admin/style.css/wp-content/plugins/webtoapp-design/admin/script.js
Script Paths
/wp-content/plugins/webtoapp-design/admin/script.js
Version Parameters
webtoapp-design/admin/style.css?ver=webtoapp-design/admin/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
wtad-options-pagewtad-section-headerwtad-options-containerwtad-flex-rowwtad-input-fieldwtad-labelwtad-inputwtad-button+9 more
HTML Comments
<!-- Handles only the webtoapp options page. -->
Data Attributes
data-wtad-option-namedata-wtad-option-value
JS Globals
WtadOptionswtad_php_vars
FAQ

Frequently Asked Questions about webtoapp.design – Convert Your WordPress Website to an App and Send Push Notifications