WP-AppKit – Mobile apps and PWA for WordPress Security & Risk Analysis

wordpress.org/plugins/wp-appkit

Important ✋: beginning with version 1.5.3, we don't support anymore native iOS app. This is a tough choice we explain here.

200 active installs v1.6.0 PHP + WP 4.0+ Updated Oct 27, 2020
androidiosmobile-appprogressive-web-apppwa
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP-AppKit – Mobile apps and PWA for WordPress Safe to Use in 2026?

Generally Safe

Score 85/100

WP-AppKit – Mobile apps and PWA for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The wp-appkit v1.6.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified attack surface points, dangerous functions, unescaped output, or file operations, coupled with the exclusive use of prepared statements for SQL queries, indicates a diligent approach to secure coding practices. Furthermore, the plugin's history shows no recorded vulnerabilities, suggesting a consistent commitment to security over time. This lack of known issues and the clean code analysis create a generally positive security profile.

However, the static analysis also reveals significant gaps that, while not directly indicating current vulnerabilities, represent potential risks. The complete absence of nonce checks and capability checks is a notable concern. While the current attack surface appears protected, these fundamental security mechanisms are not implemented, leaving the plugin vulnerable to privilege escalation or unauthorized actions if new entry points are inadvertently introduced or if existing ones are bypassed through future modifications or interactions with other plugins. The lack of taint analysis flows, while positive in its outcome, could be due to the limited scope of the analysis or a very simple codebase, not necessarily an assurance of complete taint-free operation in all scenarios.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

WP-AppKit – Mobile apps and PWA for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WP-AppKit – Mobile apps and PWA for WordPress Release Timeline

v1.6.0Current
v1.5.6
v1.5.5
v1.5.4
v1.5.3
v1.5.2
v1.5.1
v1.5
v1.2
v1.1
v1.0.2
v1.0.1
v1.0
Code Analysis
Analyzed Mar 16, 2026

WP-AppKit – Mobile apps and PWA for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared6 total queries
Attack Surface

WP-AppKit – Mobile apps and PWA for WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
filterwpak_post_datadefault-themes\q-android\php\add-custom-data.php:30
filterwpak_post_content_formatdefault-themes\q-android\php\prepare-content.php:73
filterwpak_post_datadefault-themes\q-ios\php\add-custom-data.php:30
filterwpak_post_content_formatdefault-themes\q-ios\php\prepare-content.php:73
actionplugins_loadedwp-appkit.php:27
actioninitwp-appkit.php:32
actiontemplate_redirectwp-appkit.php:33
actionadmin_noticeswp-appkit.php:35
actionadmin_initwp-appkit.php:36
Maintenance & Trust

WP-AppKit – Mobile apps and PWA for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedOct 27, 2020
PHP min version
Downloads38K

Community Trust

Rating88/100
Number of ratings9
Active installs200
Developer Profile

WP-AppKit – Mobile apps and PWA for WordPress Developer Profile

Uncategorized Creations

1 plugin · 200 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP-AppKit – Mobile apps and PWA for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-appkit/css//wp-content/plugins/wp-appkit/js//wp-content/plugins/wp-appkit/lib/settings/settings.js/wp-content/plugins/wp-appkit/lib/settings/licenses/licenses.js/wp-content/plugins/wp-appkit/lib/apps/build.js/wp-content/plugins/wp-appkit/lib/navigation/navigation.js/wp-content/plugins/wp-appkit/lib/themes/upload-themes.js/wp-content/plugins/wp-appkit/lib/shortcodes/show_hide_in_apps.js+11 more
Script Paths
/wp-content/plugins/wp-appkit/js/wp-appkit-admin.js/wp-content/plugins/wp-appkit/js/wp-appkit-app-preview.js/wp-content/plugins/wp-appkit/js/wp-appkit-app-menu.js
Version Parameters
wp-appkit/css/wp-appkit-admin.css?ver=wp-appkit/css/wp-appkit-app-preview.css?ver=wp-appkit/css/wp-appkit-app-menu.css?ver=wp-appkit/js/wp-appkit-admin.js?ver=wp-appkit/js/wp-appkit-app-preview.js?ver=wp-appkit/js/wp-appkit-app-menu.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpak_apps_listwpak_app_preview_list
JS Globals
wp_appkit_admin_configwp_appkit_preview_url
REST Endpoints
/wp-json/wp-appkit/v1/
Shortcode Output
[wpak_show_hide_in_apps]
FAQ

Frequently Asked Questions about WP-AppKit – Mobile apps and PWA for WordPress