
WMF Theme Switcher Security & Risk Analysis
wordpress.org/plugins/wmf-mobile-theme-switcherThis plugin switch themes per mobile and tablet device. Useful for the switch to a mobile theme.
Is WMF Theme Switcher Safe to Use in 2026?
Generally Safe
Score 92/100WMF Theme Switcher has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wmf-mobile-theme-switcher" plugin version 1.1 exhibits a generally strong security posture based on the provided static analysis. The absence of raw SQL queries, the high percentage of properly escaped output, and the presence of a nonce check are positive indicators. Notably, there are no recorded vulnerabilities (CVEs) for this plugin, suggesting a history of secure development or limited exposure to exploit attempts.
However, a significant concern arises from the complete lack of capability checks on any entry points. While the attack surface is small, with only two AJAX handlers and no direct REST API routes or shortcodes, the absence of authorization checks means that any user, regardless of their role, could potentially interact with these AJAX endpoints. This presents a potential risk if the functionality exposed by these handlers can be leveraged for malicious purposes, even if the code itself doesn't contain immediately apparent dangerous functions or taint flows.
In conclusion, while the plugin demonstrates good coding practices in areas like SQL and output sanitization, the lack of capability checks is a notable weakness. The pristine vulnerability history is a positive sign, but it should not entirely overshadow the importance of robust authorization for all interactive plugin components.
Key Concerns
- No capability checks on entry points
WMF Theme Switcher Security Vulnerabilities
WMF Theme Switcher Release Timeline
WMF Theme Switcher Code Analysis
Output Escaping
WMF Theme Switcher Attack Surface
AJAX Handlers 2
WordPress Hooks 12
Maintenance & Trust
WMF Theme Switcher Maintenance & Trust
Maintenance Signals
Community Trust
WMF Theme Switcher Alternatives
Any Mobile Theme Switcher
any-mobile-theme-switcher
This Plugin detects mobile browser and display the theme as the setting done from admin. Usefull for switch to Mobile Theme.
WP-Mobilizer
wp-mobilizer
WP-Mobilizer detects over 5,000 mobile devices and displays. You choose the theme you want for devices. Usefull for switch to Mobile Theme.
Frndzk Easy Mobile Theme Switcher with Theme pack
frndzk-easy-mobile-theme-switcher-with-theme-pack
Frndzk Mobile Theme Switcher and Theme Pack plugin automatically detects mobile device and shows mobile copatiable theme.
WP-Mobily
wp-mobily
Select your Mobile-Theme, only for Mobile Devices.
Equivalent Mobile Redirect
equivalent-mobile-redirect
Easy way to detect and redirect mobile visitors to the equivalent page on your mobile site. Optionally redirect all mobile users to one mobile URL.
WMF Theme Switcher Developer Profile
6 plugins · 11K total installs
How We Detect WMF Theme Switcher
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wmf-mobile-theme-switcher/assets/css/mobile-theme-switcher.css/wp-content/plugins/wmf-mobile-theme-switcher/assets/js/mobile-theme-switcher.js/wp-content/plugins/wmf-mobile-theme-switcher/assets/js/mobile-theme-switcher.jswmf-mobile-theme-switcher/assets/css/mobile-theme-switcher.css?ver=wmf-mobile-theme-switcher/assets/js/mobile-theme-switcher.js?ver=HTML / DOM Fingerprints
wmf-theme-switcher-mobile-togglewmf-theme-switcher-desktop-toggledata-wmf-theme-switcher-mobiledata-wmf-theme-switcher-desktopWMF_Mobile_Detect