Apex IDX Security & Risk Analysis

wordpress.org/plugins/apex-idx

Use the superior IDX solution to easily integrate MLS listings on your real estate website. Lead driving, responsive designs with dominant SEO.

70 active installs v3.1.3 PHP + WP 3.4.1+ Updated Sep 6, 2023
idxidx-pluginidx-solutionmlsmultiple-listing-service
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Apex IDX Safe to Use in 2026?

Generally Safe

Score 85/100

Apex IDX has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The static analysis of Apex-IDX v3.1.3 reveals significant security concerns, primarily stemming from its handling of SQL queries and output escaping. While the plugin has a clean vulnerability history and no reported CVEs, the code itself presents a high risk due to the lack of prepared statements in all 31 SQL queries and the extremely low percentage (2%) of properly escaped outputs. This indicates a high likelihood of SQL injection vulnerabilities and cross-site scripting (XSS) attacks, respectively, if malicious data is processed by these functions. The absence of nonce and capability checks on entry points is also a major red flag, suggesting that any authenticated user, or even potentially unauthenticated users depending on the context of these entry points, could trigger these vulnerable functions. Despite the absence of known vulnerabilities and a seemingly small attack surface, the internal code quality, particularly regarding data sanitization and escaping, is a critical weakness that severely compromises the plugin's security posture.

Key Concerns

  • All SQL queries use raw SQL without prepared statements.
  • Very low percentage of output escaping.
  • No nonce checks on entry points.
  • No capability checks on entry points.
Vulnerabilities
None known

Apex IDX Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Apex IDX Code Analysis

Dangerous Functions
0
Raw SQL Queries
31
0 prepared
Unescaped Output
40
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

0% prepared31 total queries

Output Escaping

2% escaped41 total outputs
Attack Surface

Apex IDX Attack Surface

Entry Points4
Unprotected0

Shortcodes 4

[realtyTech-search-form] class.RTapexIdxBase.php:84
[realtyTech-slider] class.RTapexIdxBase.php:85
[realtyTech-grid] class.RTapexIdxBase.php:86
[realtyTech-featured-market] class.RTapexIdxBase.php:87
WordPress Hooks 12
actionadmin_enqueue_scriptsclass.RTapexIdxBase.php:64
actionadmin_enqueue_scriptsclass.RTapexIdxBase.php:65
actionadmin_menuclass.RTapexIdxBase.php:66
actionadmin_menuclass.RTapexIdxBase.php:67
actionbefore_delete_postclass.RTapexIdxBase.php:68
actionsave_postclass.RTapexIdxBase.php:69
filterpage_linkclass.RTapexIdxBase.php:75
filterget_pagesclass.RTapexIdxBase.php:76
filterthe_contentclass.RTapexIdxBase.php:77
filterquery_varsclass.RTapexIdxBase.php:78
filterwidget_textclass.RTapexIdxBase.php:79
actioninitRTapexIdxGlobal.php:27
Maintenance & Trust

Apex IDX Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedSep 6, 2023
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings1
Active installs70
Developer Profile

Apex IDX Developer Profile

RealtyTech

1 plugin · 70 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Apex IDX

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/apex-idx/css/apexIdxSearchBoxWidget.css/wp-content/plugins/apex-idx/js/apexIdxsearchBoxWidget.js/wp-content/plugins/apex-idx/js/clipboard.min.js/wp-content/plugins/apex-idx/css/apexIdxFeaturedMarket.css/wp-content/plugins/apex-idx/js/apexIdxFeaturedMarket.js/wp-content/plugins/apex-idx/css/apexIdxFPSlider.css/wp-content/plugins/apex-idx/css/apexIdxFPGridSlider.css/wp-content/plugins/apex-idx/js/apexIdxInitializeSlider.js+3 more
Script Paths
https://apexidx.com/custom/apexidxWpPluginFiles/global.css
Version Parameters
apexIdxInitializeSlider.js?ver=apexIdxFPGridSlider.css?ver=

HTML / DOM Fingerprints

CSS Classes
apex-idx-search-widgetapex-idx-listing-gridapexIdxSliderapexIdxGrid
Data Attributes
data-apexidx-search-widget-optionsdata-apexidx-listing-grid-optionsdata-apexidx-slider-options
JS Globals
apexIdxSearchBoxWidgetapexIdxFeaturedMarketapexIdxInitializeSliderapexIdxbackend
Shortcode Output
[realtyTech-search-form][realtyTech-slider][realtyTech-grid][realtyTech-featured-market]
FAQ

Frequently Asked Questions about Apex IDX