
Auto Listings – Car Listings & Car Dealership Plugin for WordPress Security & Risk Analysis
wordpress.org/plugins/auto-listingsList, manage & sell cars easily. Advanced search, vehicle data from 1941, lead capture, gallery, maps. Great for car dealers.
Is Auto Listings – Car Listings & Car Dealership Plugin for WordPress Safe to Use in 2026?
Generally Safe
Score 98/100Auto Listings – Car Listings & Car Dealership Plugin for WordPress has a strong security track record. Known vulnerabilities have been patched promptly.
The Auto-Listings plugin v2.7.3 presents a mixed security posture. While it demonstrates good practices in output escaping and avoids dangerous functions, its attack surface and vulnerability history raise concerns. The presence of two unprotected AJAX handlers represents a significant risk, as these can be leveraged by attackers to execute actions without proper authentication. The taint analysis, although not revealing critical or high severity flows, did identify one flow with an unsanitized path, which could potentially lead to vulnerabilities if not handled carefully. The plugin's vulnerability history, with two medium-severity CVEs, both related to Cross-Site Scripting, indicates a past pattern of input sanitization issues. The fact that the last vulnerability was recorded in late 2025 (though this date might be hypothetical for the purpose of this analysis) and is currently unpatched is a major concern, suggesting active exploitation or ongoing risks from known flaws.
Key Concerns
- Unprotected AJAX handlers
- Flow with unsanitized path
- Unpatched CVEs (medium)
- SQL queries not fully prepared
- Limited nonce checks
- No capability checks on AJAX
Auto Listings – Car Listings & Car Dealership Plugin for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Auto Listings <= 2.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Auto Listings <= 2.6.5 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode
Auto Listings – Car Listings & Car Dealership Plugin for WordPress Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Auto Listings – Car Listings & Car Dealership Plugin for WordPress Attack Surface
AJAX Handlers 3
Shortcodes 11
WordPress Hooks 108
Maintenance & Trust
Auto Listings – Car Listings & Car Dealership Plugin for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Auto Listings – Car Listings & Car Dealership Plugin for WordPress Alternatives
Inventory Presser – Car Dealer Listings
inventory-presser
Vehicle inventory management for dealerships. Supports multiple car lot locations. Provides listing templates & photo sliders. Multisite compatible.
Motors VIN Decoder
motors-vin-decoder
Motors VIN Decoder & Vehicle History Check is free plugin to decode your vehicle VIN. Free version is based on USA National Highway Traffic Safety …
Directorykit Car Dealer Addon
directorykit-car-dealer-addon
Transforms WordPress into a car dealership portal with demo listings; fully customizable with Elementor for automotive sites.
Motors – Car Dealership & Classified Listings Plugin
motors-car-dealership-classified-listings
Manage classified listings with WordPress, and allow users to post classified listings directly to your website.
DirectoryPress Frontend
directorypress-frontend
This plugin provides frontend listing functionality for [DirectoryPress - Directory Listing Plugin](https://designinvento.
Auto Listings – Car Listings & Car Dealership Plugin for WordPress Developer Profile
2 plugins · 3K total installs
How We Detect Auto Listings – Car Listings & Car Dealership Plugin for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/auto-listings/assets/admin/css/extensions.css/wp-content/plugins/auto-listings/assets/admin/css/auto-listings.css/wp-content/plugins/auto-listings/assets/admin/css/settings.css/wp-content/plugins/auto-listings/assets/css/auto-listings-icons.css/wp-content/plugins/auto-listings/assets/css/font-awesome.min.css/wp-content/plugins/auto-listings/assets/css/sumoselect.min.css/wp-content/plugins/auto-listings/assets/css/auto-listings.css/wp-content/plugins/auto-listings/assets/js/sumoselect.min.js+3 more/wp-content/plugins/auto-listings/assets/js/sumoselect.min.js/wp-content/plugins/auto-listings/assets/js/lightslider.js/wp-content/plugins/auto-listings/assets/js/auto-listings.jsauto-listings/assets/admin/css/extensions.css?ver=auto-listings/assets/admin/css/auto-listings.css?ver=auto-listings/assets/admin/css/settings.css?ver=auto-listings/assets/css/auto-listings-icons.css?ver=auto-listings/assets/css/font-awesome.min.css?ver=auto-listings/assets/css/sumoselect.min.css?ver=auto-listings/assets/css/auto-listings.css?ver=auto-listings/assets/js/sumoselect.min.js?ver=auto-listings/assets/js/lightslider.js?ver=auto-listings/assets/css/lightslider.css?ver=auto-listings/assets/js/auto-listings.js?ver=HTML / DOM Fingerprints
auto-listingsal-buttonal-settings-pagedata-map_widthdata-map_heightdata-map_zoomdata-latdata-lngdata-address+2 moreauto_listings