
WP Is Mobile Text Widget Security & Risk Analysis
wordpress.org/plugins/wp-is-mobile-text-widgetWP Is Mobile Text Widget plugin adds text widget that switched display text using wp_is_mobile() function whether the device is mobile or not.
Is WP Is Mobile Text Widget Safe to Use in 2026?
Generally Safe
Score 92/100WP Is Mobile Text Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of wp-is-mobile-text-widget v1.2.1 reveals a generally strong security posture. The plugin exhibits good practices by having zero identified AJAX handlers, REST API routes, shortcodes, or cron events, indicating a minimal attack surface. Crucially, there are no identified dangerous functions, and all SQL queries are properly prepared, mitigating common SQL injection risks. The output escaping is also robust, with 85% of outputs being properly escaped, which is a positive sign for preventing cross-site scripting (XSS) vulnerabilities. The absence of any recorded vulnerabilities in its history further reinforces this positive outlook.
However, a notable concern is the complete absence of nonce checks. While the attack surface is small, this absence could be a weakness if new entry points are introduced or if existing code interactions are not fully understood in a broader context. The presence of capability checks, while present, is not a complete substitute for nonce checks, especially for actions that might be triggered by unauthenticated or lower-privileged users if not properly guarded elsewhere. The taint analysis shows no flows, which is excellent, but it's worth noting that the total flows analyzed is 0, suggesting the analysis might not have been comprehensive or that the plugin's functionality is very limited.
In conclusion, wp-is-mobile-text-widget v1.2.1 appears to be a secure plugin based on the provided data, with a small attack surface and good coding practices in place regarding SQL and output handling. The main area for improvement and a potential risk, albeit a theoretical one given the lack of identified issues, is the complete absence of nonce checks. The vulnerability history is clean, which is a strong indicator of a well-maintained and secure plugin.
Key Concerns
- Missing nonce checks on entry points
WP Is Mobile Text Widget Security Vulnerabilities
WP Is Mobile Text Widget Release Timeline
WP Is Mobile Text Widget Code Analysis
Output Escaping
WP Is Mobile Text Widget Attack Surface
WordPress Hooks 2
Maintenance & Trust
WP Is Mobile Text Widget Maintenance & Trust
Maintenance Signals
Community Trust
WP Is Mobile Text Widget Alternatives
Widget Context
widget-context
Show and hide widgets on specific posts, pages and sections of your site.
Enhanced Text Widget
enhanced-text-widget
An enhanced version of the text widget that supports Text, HTML, CSS, JavaScript, Flash, Shortcodes and PHP with linkable widget title.
WP Editor Widget
wp-editor-widget
WP Editor Widget adds a rich text widget where the content is edited using the standard WordPress visual editor.
Widget Content Blocks
wysiwyg-widgets
Edit widget content using the default WordPress visual editor and media uploading functionality. Create widgets like you would create posts or pages.
Podium
podium
Add and customize Podium's Web Suite tools to your WordPress website
WP Is Mobile Text Widget Developer Profile
11 plugins · 39K total installs
How We Detect WP Is Mobile Text Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-is-mobile-text-widget/inc/class-wp-is-mobile-text-widget.phpHTML / DOM Fingerprints
widget_is_mobile_textwp-is-mobile-text-widget