
WP-AppKit – Mobile apps and PWA for WordPress Security & Risk Analysis
wordpress.org/plugins/wp-appkitImportant ✋: beginning with version 1.5.3, we don't support anymore native iOS app. This is a tough choice we explain here.
Is WP-AppKit – Mobile apps and PWA for WordPress Safe to Use in 2026?
Generally Safe
Score 85/100WP-AppKit – Mobile apps and PWA for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-appkit v1.6.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified attack surface points, dangerous functions, unescaped output, or file operations, coupled with the exclusive use of prepared statements for SQL queries, indicates a diligent approach to secure coding practices. Furthermore, the plugin's history shows no recorded vulnerabilities, suggesting a consistent commitment to security over time. This lack of known issues and the clean code analysis create a generally positive security profile.
However, the static analysis also reveals significant gaps that, while not directly indicating current vulnerabilities, represent potential risks. The complete absence of nonce checks and capability checks is a notable concern. While the current attack surface appears protected, these fundamental security mechanisms are not implemented, leaving the plugin vulnerable to privilege escalation or unauthorized actions if new entry points are inadvertently introduced or if existing ones are bypassed through future modifications or interactions with other plugins. The lack of taint analysis flows, while positive in its outcome, could be due to the limited scope of the analysis or a very simple codebase, not necessarily an assurance of complete taint-free operation in all scenarios.
Key Concerns
- No nonce checks implemented
- No capability checks implemented
WP-AppKit – Mobile apps and PWA for WordPress Security Vulnerabilities
WP-AppKit – Mobile apps and PWA for WordPress Release Timeline
WP-AppKit – Mobile apps and PWA for WordPress Code Analysis
SQL Query Safety
WP-AppKit – Mobile apps and PWA for WordPress Attack Surface
WordPress Hooks 9
Maintenance & Trust
WP-AppKit – Mobile apps and PWA for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
WP-AppKit – Mobile apps and PWA for WordPress Alternatives
miTT PWA FREE WP
mitt-pwa
miTT PWA FREE WP transforms your WordPress Website into a Progressive Web App (PWA) and makes it offline ready using Service Workers.
Super Progressive Web Apps
super-progressive-web-apps
SuperPWA helps you convert your WordPress website into a Progressive Web App instantly.
WPMobile.App
wpappninja
Android and iOS mobile application. Easy setup, free test.
Mobile Smart App Banner
mobile-smart-app-banner
Transform your mobile website visitors into app users with intelligent smart app banners that boost downloads across iOS and Android devices.
Progressify – All-in-One Progressive Web App (PWA) on Autopilot
progressify
Turn your site into an app-like PWA with install prompts, offline use, push notifications, and more to boost engagement, repeat visits, and sales.
WP-AppKit – Mobile apps and PWA for WordPress Developer Profile
1 plugin · 200 total installs
How We Detect WP-AppKit – Mobile apps and PWA for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-appkit/css//wp-content/plugins/wp-appkit/js//wp-content/plugins/wp-appkit/lib/settings/settings.js/wp-content/plugins/wp-appkit/lib/settings/licenses/licenses.js/wp-content/plugins/wp-appkit/lib/apps/build.js/wp-content/plugins/wp-appkit/lib/navigation/navigation.js/wp-content/plugins/wp-appkit/lib/themes/upload-themes.js/wp-content/plugins/wp-appkit/lib/shortcodes/show_hide_in_apps.js+11 more/wp-content/plugins/wp-appkit/js/wp-appkit-admin.js/wp-content/plugins/wp-appkit/js/wp-appkit-app-preview.js/wp-content/plugins/wp-appkit/js/wp-appkit-app-menu.jswp-appkit/css/wp-appkit-admin.css?ver=wp-appkit/css/wp-appkit-app-preview.css?ver=wp-appkit/css/wp-appkit-app-menu.css?ver=wp-appkit/js/wp-appkit-admin.js?ver=wp-appkit/js/wp-appkit-app-preview.js?ver=wp-appkit/js/wp-appkit-app-menu.js?ver=HTML / DOM Fingerprints
wpak_apps_listwpak_app_preview_listwp_appkit_admin_configwp_appkit_preview_url/wp-json/wp-appkit/v1/[wpak_show_hide_in_apps]