Connect CRM RealState Security & Risk Analysis

wordpress.org/plugins/connect-crm-realstate

Import real estate properties from Inmovilla and Anaconda CRM systems into WordPress as custom post types.

0 active installs v1.2.0 PHP 7.4+ WP 5.8+ Updated Mar 10, 2026
anacondacrminmovillapropertiesreal-estate
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Connect CRM RealState Safe to Use in 2026?

Generally Safe

Score 100/100

Connect CRM RealState has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 24d ago
Risk Assessment

The "connect-crm-realstate" plugin version 1.2.1 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a clean taint analysis report are highly positive indicators, suggesting the plugin has been developed with security in mind and has not been a target of significant past vulnerabilities. The code signals also show good practices, with all SQL queries using prepared statements and a high percentage of output escaping. The presence of nonce and capability checks on entry points, despite a small number of AJAX handlers, further strengthens its defense against common attack vectors.

However, there are minor areas for potential improvement. While the number of entry points is small and none are reported as unprotected, a more granular breakdown of authorization checks on AJAX handlers would be beneficial. The static analysis indicates 3 AJAX handlers, but only 1 capability check is noted. This could imply that 2 AJAX handlers might lack specific capability checks, although the data doesn't explicitly confirm this as a vulnerability, it's a potential blind spot. Additionally, the presence of bundled libraries like Select2 could introduce risks if not kept up-to-date, though no specific version issues are mentioned in the provided data.

In conclusion, "connect-crm-realstate" v1.2.1 appears to be a relatively secure plugin with a good track record. The development team seems to follow best practices regarding SQL and output sanitization. The main areas to monitor would be ensuring all AJAX endpoints have appropriate authorization checks and keeping bundled libraries updated. The absence of any vulnerability history is a significant strength.

Key Concerns

  • Potential missing capability checks on AJAX handlers
  • Bundled library (Select2) may require version updates
Vulnerabilities
None known

Connect CRM RealState Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Connect CRM RealState Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
16
140 escaped
Nonce Checks
3
Capability Checks
1
File Operations
3
External Requests
3
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

100% prepared6 total queries

Output Escaping

90% escaped156 total outputs
Attack Surface

Connect CRM RealState Attack Surface

Entry Points7
Unprotected0

AJAX Handlers 3

authwp_ajax_ccrmre_auto_map_fieldsincludes\class-iip-admin.php:46
authwp_ajax_ccrmre_manual_importincludes\class-iip-import.php:50
authwp_ajax_ccrmre_get_import_statsincludes\class-iip-import.php:51

Shortcodes 4

[ccrmre_property_gallery] includes\class-gallery.php:40
[property_gallery] includes\class-gallery.php:41
[ccrmre_property_info] includes\class-property-info.php:40
[property_info] includes\class-property-info.php:41
WordPress Hooks 15
actionplugins_loadedconnect-crm-realstate.php:55
actionplugins_loadedconnect-crm-realstate.php:60
actionadmin_noticesconnect-crm-realstate.php:65
filterpost_thumbnail_htmlincludes\class-featured-image-url.php:30
filterthe_contentincludes\class-gallery.php:45
actionwp_enqueue_scriptsincludes\class-gallery.php:49
actionadmin_menuincludes\class-iip-admin.php:44
actionadmin_noticesincludes\class-iip-admin.php:45
actionadmin_initincludes\class-iip-admin.php:115
actionadmin_enqueue_scriptsincludes\class-iip-admin.php:116
actionadmin_enqueue_scriptsincludes\class-iip-import.php:49
actioninitincludes\class-iip-post-type.php:45
actionadd_meta_boxesincludes\class-iip-post-type.php:48
filterthe_contentincludes\class-property-info.php:46
actionwp_enqueue_scriptsincludes\class-property-info.php:50
Maintenance & Trust

Connect CRM RealState Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedMar 10, 2026
PHP min version7.4
Downloads119

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Connect CRM RealState Developer Profile

Close·technology

3 plugins · 1K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Connect CRM RealState

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/connect-crm-realstate/includes/assets/gallery.css/wp-content/plugins/connect-crm-realstate/includes/assets/gallery.js
Script Paths
/wp-content/plugins/connect-crm-realstate/includes/assets/gallery.js
Version Parameters
connect-crm-realstate/includes/assets/gallery.css?ver=connect-crm-realstate/includes/assets/gallery.js?ver=

HTML / DOM Fingerprints

CSS Classes
ccrmre-property-galleryccrmre-gallery-mainccrmre-gallery-prevccrmre-gallery-sliderccrmre-gallery-slideccrmre-gallery-nextccrmre-gallery-counterccrmre-gallery-current+3 more
Data Attributes
data-index
Shortcode Output
[ccrmre_property_gallery][property_gallery]
FAQ

Frequently Asked Questions about Connect CRM RealState