
WPMobile Apps Security & Risk Analysis
wordpress.org/plugins/wpmobile-appsCreate a mobile WordPress website experience on your website.
Is WPMobile Apps Safe to Use in 2026?
Generally Safe
Score 100/100WPMobile Apps has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wpmobile-apps" plugin v1.0.2 presents a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and has a clean vulnerability history with no known CVEs. This suggests a degree of developer diligence in addressing known security issues.
However, there are significant concerns arising from the static analysis. The presence of two AJAX handlers without authentication checks creates a direct attack vector for unauthorized actions. Furthermore, the static analysis reveals a concerning trend in output sanitization, with only 3% of outputs being properly escaped. This significantly increases the risk of Cross-Site Scripting (XSS) vulnerabilities, especially when combined with the 8 identified taint flows with unsanitized paths. While these taint flows are not flagged as critical or high severity, the sheer number and lack of sanitization are worrying.
The plugin also utilizes a potentially outdated bundled library, Select2, which could harbor its own unpatched vulnerabilities if not kept up-to-date. The use of the `create_function` is a deprecated and insecure practice that should be avoided. Despite the lack of known CVEs, the identified code signals and taint analysis warrant careful attention and remediation to improve the plugin's overall security.
Key Concerns
- AJAX handlers without authentication checks
- Low percentage of properly escaped output
- Taint flows with unsanitized paths (8 total)
- Use of deprecated and insecure function 'create_function'
- Bundled library (Select2) potential for unpatched vulns
WPMobile Apps Security Vulnerabilities
WPMobile Apps Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WPMobile Apps Attack Surface
AJAX Handlers 2
Shortcodes 20
WordPress Hooks 21
Maintenance & Trust
WPMobile Apps Maintenance & Trust
Maintenance Signals
Community Trust
WPMobile Apps Alternatives
WPapptouch
wpapptouch
WPapptouch is a WordPress plugin & theme to transform your WordPress website to a Native like application for mobile.
WPtouch – Make your WordPress Website Mobile-Friendly
wptouch
With just a few clicks, make your WordPress website mobile-friendly (iPhone, Android, and more). Recommended by Google, it will instantly enable a mob …
AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker)
appmysite
Turn your WordPress or WooCommerce site into a native Android & iOS app in minutes — no coding required.
AppPresser – Mobile App Framework
apppresser
Connect your WordPress site to a native mobile app.
MOBILOOK — Mobile View & Mobile‑Friendly Test
mobilook
Instant mobile view of website (pages, posts, products) for responsive web design on phone (+ dualscreen). This plugin also offers helpful tools on ea …
WPMobile Apps Developer Profile
1 plugin · 10 total installs
How We Detect WPMobile Apps
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpmobile-apps/apps/call-us/app.js/wp-content/plugins/wpmobile-apps/apps/call-us/app.css/wp-content/plugins/wpmobile-apps/apps/contact-us/app.js/wp-content/plugins/wpmobile-apps/apps/contact-us/app.css/wp-content/plugins/wpmobile-apps/themes/mobilissimo/css/style.css/wp-content/plugins/wpmobile-apps/apps/call-us/app.js/wp-content/plugins/wpmobile-apps/apps/contact-us/app.jswpmobile-apps/apps/call-us/app.js?ver=wpmobile-apps/apps/call-us/app.css?ver=wpmobile-apps/apps/contact-us/app.js?ver=wpmobile-apps/apps/contact-us/app.css?ver=wpmobile-apps/themes/mobilissimo/css/style.css?ver=HTML / DOM Fingerprints
wpmob-call-uswpmob-contact-uswpmob_app_call_us_orderwpmob_app_call_us_labelwpmob_app_call_us_text_iconwpmob_app_call_us_phonewpmob_app_contact_us_orderwpmob_app_contact_us_label+2 more