
WPMobile.App Security & Risk Analysis
wordpress.org/plugins/wpappninjaAndroid and iOS mobile application. Easy setup, free test.
Is WPMobile.App Safe to Use in 2026?
Generally Safe
Score 89/100WPMobile.App has a strong security track record. Known vulnerabilities have been patched promptly.
The wpappninja plugin v11.75 presents a mixed security posture. While it demonstrates some good practices, such as a high percentage of SQL queries using prepared statements and a reasonable number of nonce and capability checks, significant concerns exist. The plugin has a considerable attack surface, with 36 total entry points, and notably, 3 of these (AJAX handlers) lack authentication checks, creating potential avenues for unauthorized actions. The taint analysis is particularly concerning, revealing 25 high-severity flows with unsanitized paths, indicating a strong possibility of sensitive data being mishandled or manipulated. Furthermore, only 12% of output is properly escaped, raising the risk of Cross-Site Scripting (XSS) vulnerabilities. The plugin's vulnerability history, with 9 known CVEs including high and medium severity issues like Open Redirect, Code Injection, and XSS, reinforces these concerns. The recency of the last vulnerability (2025) suggests ongoing security challenges, despite no currently unpatched CVEs.
Key Concerns
- AJAX handlers without auth checks
- High severity taint flows with unsanitized paths
- Low percentage of properly escaped output
- Multiple known vulnerabilities (High/Medium)
- Bundled libraries (potential for outdated versions)
WPMobile.App Security Vulnerabilities
CVEs by Year
Severity Breakdown
9 total CVEs
WPMobile.App <= 11.71 - Unauthenticated Stored Cross-Site Scripting
WPMobile.App <= 11.56 - Open Redirect via 'redirect' Parameter
WPMobile.App — Android and iOS Mobile Application <= 11.52 - Unauthenticated Arbitrary Shortcode Execution
WPMobile.App <= 11.50 - Reflected Cross-Site Scripting
WPMobile.App <= 11.48 - Reflected Cross-Site Scripting
WPMobile.App — Android and iOS Mobile Application <= 11.41 - Reflected Cross-Site Scripting
WPMobile.App <= 11.20 - Authenticated (Administrator+) Stored Cross-Site Scripting
WPMobile.App — Android and iOS Mobile Application <= 11.18 - Authenticated (Administrator+) Stored Cross-Site Scripting
WPMobile.App — Android and iOS Mobile Application <= 11.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodes
WPMobile.App Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WPMobile.App Attack Surface
AJAX Handlers 3
Shortcodes 33
WordPress Hooks 136
Scheduled Events 9
Maintenance & Trust
WPMobile.App Maintenance & Trust
Maintenance Signals
Community Trust
WPMobile.App Alternatives
Mobile Smart App Banner
mobile-smart-app-banner
Transform your mobile website visitors into app users with intelligent smart app banners that boost downloads across iOS and Android devices.
APPExperts – Mobile App Builder for WordPress | WooCommerce to iOS and Android Apps
appexperts
APPExperts is a freemium mobile app builder that gives you the power to turn your WordPress-powered website into a mobile application for iOS and Andr …
Knowband Mobile App Builder
knowband-mobile-app-builder-for-woocommerce
The Knowband Mobile App Builder converts your online store into a pair of native Android & iOS apps without any coding.
miTT PWA FREE WP
mitt-pwa
miTT PWA FREE WP transforms your WordPress Website into a Progressive Web App (PWA) and makes it offline ready using Service Workers.
Swipecart
swipecart
Launch a world-class mobile app for your brand within minutes, without codes. Ready-to-market feature-rich app for your e-commerce store instantly.
WPMobile.App Developer Profile
2 plugins · 14K total installs
How We Detect WPMobile.App
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpappninja/assets/css/wpappninja.css/wp-content/plugins/wpappninja/assets/js/wpappninja.js/wp-content/plugins/wpappninja/assets/svg/ic_wpappninja.svg/wp-content/plugins/wpappninja/assets/js/wpappninja.jswpappninja/assets/css/wpappninja.css?ver=wpappninja/assets/js/wpappninja.js?ver=HTML / DOM Fingerprints
wpappninja-buttondata-wpappninja-idwindow.WPAPPNINJA_SETTINGWPAPPNINJA_SETTING[wpappninja_qr_code]