
CarDealerPress Security & Risk Analysis
wordpress.org/plugins/cardealerpressIn order to use CarDealerPress a subscription is required with DealerTrend. The plugin utilizes their API to pull automotive data.
Is CarDealerPress Safe to Use in 2026?
Generally Safe
Score 98/100CarDealerPress has a strong security track record. Known vulnerabilities have been patched promptly.
The cardealerpress plugin, version 6.9.2603.00, exhibits a mixed security posture. While it demonstrates good practices in areas like SQL query preparation (95%) and output escaping (96%), significant concerns arise from its attack surface. A notable 7 out of 12 entry points lack authentication checks, including all 7 AJAX handlers. This presents a considerable risk of unauthorized access and manipulation of plugin functionalities. The presence of a `unserialize` dangerous function, even without immediate taint flow indicators, is a red flag that could be exploited in conjunction with other vulnerabilities if user-controlled data is unserialized. The vulnerability history, while currently showing no unpatched CVEs, reveals a past of two medium severity vulnerabilities, both related to Cross-site Scripting. This pattern suggests a tendency for input sanitization issues, which, combined with the large number of unprotected entry points, could lead to future exploitable XSS or other injection vulnerabilities.
Key Concerns
- AJAX handlers without authentication
- Dangerous function: unserialize
- Past XSS vulnerabilities indicate input sanitization issues
- Bundled library: Select2 (potential for outdated version)
CarDealerPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
CarDealerPress <= 6.8.2505.00 - Authenticated (Contributor+) Stored Cross-Site Scripting via saleclass Parameter
CarDealerPress <= 6.6.2410.02 - Reflected Cross-Site Scripting
CarDealerPress Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
CarDealerPress Attack Surface
AJAX Handlers 7
Shortcodes 5
WordPress Hooks 46
Scheduled Events 4
Maintenance & Trust
CarDealerPress Maintenance & Trust
Maintenance Signals
Community Trust
CarDealerPress Alternatives
Vehizo
vehizo-vehicle-management
Professional vehicle management for WordPress. Perfect for car dealerships with advanced filtering and contact forms.
Motors VIN Decoder
motors-vin-decoder
Motors VIN Decoder & Vehicle History Check is free plugin to decode your vehicle VIN. Free version is based on USA National Highway Traffic Safety …
Automotive Inventory Importer – Sync Car Dealer Feeds
automotive-feed-import
Automatically update your car inventory on your website. No manual entry needed. Stop wasting hours uploading cars one by one.
Formulas
formulas
Automotive formulas for car enthusiast web sites
Directorykit Car Dealer Addon
directorykit-car-dealer-addon
Transforms WordPress into a car dealership portal with demo listings; fully customizable with Elementor for automotive sites.
CarDealerPress Developer Profile
1 plugin · 40 total installs
How We Detect CarDealerPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cardealerpress/assets/css/style.css/wp-content/plugins/cardealerpress/assets/css/responsive.css/wp-content/plugins/cardealerpress/assets/css/cdp-custom.css/wp-content/plugins/cardealerpress/assets/css/cdp-swiper.css/wp-content/plugins/cardealerpress/assets/css/cdp-animate.css/wp-content/plugins/cardealerpress/assets/js/bootstrap.js/wp-content/plugins/cardealerpress/assets/js/cardealerpress.js/wp-content/plugins/cardealerpress/assets/js/cardealerpress-swiper.js+8 more/wp-content/plugins/cardealerpress/assets/js/bootstrap.js/wp-content/plugins/cardealerpress/assets/js/cardealerpress.js/wp-content/plugins/cardealerpress/assets/js/cardealerpress-swiper.js/wp-content/plugins/cardealerpress/assets/js/bootstrap-datepicker.js/wp-content/plugins/cardealerpress/assets/js/cdp-custom.js/wp-content/plugins/cardealerpress/assets/js/jquery.form.js+1 morecardealerpress/assets/css/style.css?ver=cardealerpress/assets/css/responsive.css?ver=cardealerpress/assets/css/cdp-custom.css?ver=cardealerpress/assets/css/cdp-swiper.css?ver=cardealerpress/assets/css/cdp-animate.css?ver=cardealerpress/assets/js/bootstrap.js?ver=cardealerpress/assets/js/cardealerpress.js?ver=cardealerpress/assets/js/cardealerpress-swiper.js?ver=cardealerpress/assets/js/bootstrap-datepicker.js?ver=cardealerpress/assets/js/cdp-custom.js?ver=cardealerpress/assets/js/jquery.form.js?ver=cardealerpress/assets/js/select2.min.js?ver=cardealerpress/assets/css/bootstrap.css?ver=cardealerpress/assets/css/cdp-bootstrap-select.css?ver=cardealerpress/assets/css/bootstrap-datepicker.css?ver=cardealerpress/assets/css/select2.min.css?ver=HTML / DOM Fingerprints
cdp-banner-cdp-inventory-cdp-listing-cdp-widget-<!-- CarDealerPress Plugin --><!-- CarDealerPress Shortcode -->data-cdp-car-iddata-cdp-inventory-iddata-cdp-widget-idcdp_ajax_objectcdp_varscardealerpress/wp-json/cardealerpress/v1/[cdp-listing][cdp-widget][cdp-banner][cdp-inventory]