WP to Android App Security & Risk Analysis

wordpress.org/plugins/wp-to-android-app

WP to Android is simply turn your website using Kites.Dev App builder Service.

30 active installs v1.9.3 PHP 5.6+ WP 5.1+ Updated May 29, 2022
androidfree-android-appnative-appwordpress-to-androidwp2android
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP to Android App Safe to Use in 2026?

Generally Safe

Score 85/100

WP to Android App has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The plugin 'wp-to-android-app' v1.9.3 exhibits a mixed security posture. On one hand, it demonstrates good practices by utilizing prepared statements for all SQL queries, having no recorded vulnerabilities or CVEs, and performing no file operations. However, significant concerns arise from the attack surface analysis. The plugin exposes a single unprotected REST API route, which presents a direct entry point for potential exploitation without any authentication or permission checks. Furthermore, the low percentage of properly escaped output (36%) indicates a risk of cross-site scripting (XSS) vulnerabilities, as user-supplied data might be rendered directly into the HTML without proper sanitization. The absence of nonce checks and capability checks on its exposed entry points exacerbates these risks.

Key Concerns

  • Unprotected REST API route
  • Low output escaping percentage
  • Missing capability checks
  • Missing nonce checks
Vulnerabilities
None known

WP to Android App Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WP to Android App Release Timeline

v1.9.3Current
v1.9.2
v1.9.1
v1.9
v1.8.28
v1.0
Code Analysis
Analyzed Apr 16, 2026

WP to Android App Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

36% escaped25 total outputs
Attack Surface
1 unprotected

WP to Android App Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

GET/wp-json/wptonativeandroidsettings/v1/settingsincludes/init.php:4
WordPress Hooks 4
actionrest_api_initincludes/init.php:3
actionadmin_menuincludes/settings.php:6
actionadmin_initincludes/settings.php:7
actionadmin_enqueue_scriptswptonativeandroid.php:25
Maintenance & Trust

WP to Android App Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedMay 29, 2022
PHP min version5.6
Downloads6K

Community Trust

Rating100/100
Number of ratings4
Active installs30
Developer Profile

WP to Android App Developer Profile

jabedbd

5 plugins · 80 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP to Android App

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-to-android-app/js/wptonativeandroid-admin.js
Script Paths
/wp-content/plugins/wp-to-android-app/js/wptonativeandroid-admin.js

HTML / DOM Fingerprints

REST Endpoints
/wp-json/wptonativeandroidsettings/v1/settings
FAQ

Frequently Asked Questions about WP to Android App