
CarDealerPress Security & Risk Analysis
wordpress.org/plugins/cardealerpressIn order to use CarDealerPress a subscription is required with DealerTrend. The plugin utilizes their API to pull automotive data.
Is CarDealerPress Safe to Use in 2026?
Generally Safe
Score 99/100CarDealerPress has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The cardealerpress plugin, version 6.9.2603.00, exhibits a mixed security posture. While it demonstrates good practices in areas like SQL query preparation (95%) and output escaping (96%), significant concerns arise from its attack surface. A notable 7 out of 12 entry points lack authentication checks, including all 7 AJAX handlers. This presents a considerable risk of unauthorized access and manipulation of plugin functionalities. The presence of a `unserialize` dangerous function, even without immediate taint flow indicators, is a red flag that could be exploited in conjunction with other vulnerabilities if user-controlled data is unserialized. The vulnerability history, while currently showing no unpatched CVEs, reveals a past of two medium severity vulnerabilities, both related to Cross-site Scripting. This pattern suggests a tendency for input sanitization issues, which, combined with the large number of unprotected entry points, could lead to future exploitable XSS or other injection vulnerabilities.
Key Concerns
- AJAX handlers without authentication
- Dangerous function: unserialize
- Past XSS vulnerabilities indicate input sanitization issues
- Bundled library: Select2 (potential for outdated version)
CarDealerPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
CarDealerPress <= 6.8.2505.00 - Authenticated (Contributor+) Stored Cross-Site Scripting via saleclass Parameter
CarDealerPress <= 6.6.2410.02 - Reflected Cross-Site Scripting
CarDealerPress Release Timeline
CarDealerPress Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
CarDealerPress Attack Surface
AJAX Handlers 7
Shortcodes 5
WordPress Hooks 46
Scheduled Events 4
Maintenance & Trust
CarDealerPress Maintenance & Trust
Maintenance Signals
Community Trust
CarDealerPress Alternatives
Vehizo
vehizo-vehicle-management
Professional vehicle management for WordPress. Perfect for car dealerships with advanced filtering and contact forms.
Motors VIN Decoder
motors-vin-decoder
Motors VIN Decoder & Vehicle History Check is free plugin to decode your vehicle VIN. Free version is based on USA National Highway Traffic Safety …
Directorykit Car Dealer Addon
directorykit-car-dealer-addon
Transforms WordPress into a car dealership portal with demo listings; fully customizable with Elementor for automotive sites.
Automotive Inventory Importer – Sync Car Dealer Feeds
automotive-feed-import
Sync your car dealer inventory from XML or CSV feeds to WordPress. Auto-import vehicles with field mapping, search, gallery & more.
Formulas
formulas
Automotive formulas for car enthusiast web sites
CarDealerPress Developer Profile
1 plugin · 30 total installs
How We Detect CarDealerPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cardealerpress/assets/css/style.css/wp-content/plugins/cardealerpress/assets/css/responsive.css/wp-content/plugins/cardealerpress/assets/css/cdp-custom.css/wp-content/plugins/cardealerpress/assets/css/cdp-swiper.css/wp-content/plugins/cardealerpress/assets/css/cdp-animate.css/wp-content/plugins/cardealerpress/assets/js/bootstrap.js/wp-content/plugins/cardealerpress/assets/js/cardealerpress.js/wp-content/plugins/cardealerpress/assets/js/cardealerpress-swiper.js+8 more/wp-content/plugins/cardealerpress/assets/js/bootstrap.js/wp-content/plugins/cardealerpress/assets/js/cardealerpress.js/wp-content/plugins/cardealerpress/assets/js/cardealerpress-swiper.js/wp-content/plugins/cardealerpress/assets/js/bootstrap-datepicker.js/wp-content/plugins/cardealerpress/assets/js/cdp-custom.js/wp-content/plugins/cardealerpress/assets/js/jquery.form.js+1 morecardealerpress/assets/css/style.css?ver=cardealerpress/assets/css/responsive.css?ver=cardealerpress/assets/css/cdp-custom.css?ver=cardealerpress/assets/css/cdp-swiper.css?ver=cardealerpress/assets/css/cdp-animate.css?ver=cardealerpress/assets/js/bootstrap.js?ver=cardealerpress/assets/js/cardealerpress.js?ver=cardealerpress/assets/js/cardealerpress-swiper.js?ver=cardealerpress/assets/js/bootstrap-datepicker.js?ver=cardealerpress/assets/js/cdp-custom.js?ver=cardealerpress/assets/js/jquery.form.js?ver=cardealerpress/assets/js/select2.min.js?ver=cardealerpress/assets/css/bootstrap.css?ver=cardealerpress/assets/css/cdp-bootstrap-select.css?ver=cardealerpress/assets/css/bootstrap-datepicker.css?ver=cardealerpress/assets/css/select2.min.css?ver=HTML / DOM Fingerprints
cdp-banner-cdp-inventory-cdp-listing-cdp-widget-<!-- CarDealerPress Plugin --><!-- CarDealerPress Shortcode -->data-cdp-car-iddata-cdp-inventory-iddata-cdp-widget-idcdp_ajax_objectcdp_varscardealerpress/wp-json/cardealerpress/v1/[cdp-listing][cdp-widget][cdp-banner][cdp-inventory]