Easy MLS Listings Import Security & Risk Analysis

wordpress.org/plugins/easy-mls-listings-import

Easy MLS Listings Import lets you easily display a real estate agent’s MLS listings. Listings update automatically after set-up for low maintenance!

100 active installs v2.1.0 PHP 7.4+ WP 4.0+ Updated Feb 18, 2025
home-asapmlsreal-estaterealtorrealty
91
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 17, 2025
Safety Verdict

Is Easy MLS Listings Import Safe to Use in 2026?

Generally Safe

Score 91/100

Easy MLS Listings Import has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Feb 17, 2025Updated 1yr ago
Risk Assessment

The static analysis for easy-mls-listings-import v2.1.0 reveals a strong adherence to secure coding practices in several key areas. There are no identified dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. The absence of file operations and external HTTP requests further reduces the potential attack surface from this plugin's core code.

However, the static analysis does highlight significant gaps in security control. The plugin has zero identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events that are protected by authentication or capability checks. While the total number of entry points is zero, this lack of explicit checks, combined with zero nonces and zero capability checks, suggests that any newly introduced functionality might be inherently insecure if not carefully audited. The vulnerability history shows one known CVE, a medium-severity cross-site scripting vulnerability, which was patched as of the last reported date. The fact that there are no currently unpatched vulnerabilities is positive, but the presence of past XSS issues is a recurring concern.

In conclusion, while the current version of easy-mls-listings-import v2.1.0 demonstrates good foundational security with its SQL and output handling, the lack of explicit security checks on its (albeit absent) entry points is a notable weakness. The past XSS vulnerability indicates a potential for such issues to arise. The plugin's security posture is therefore mixed, with good core coding practices but potential vulnerabilities stemming from a lack of robust access control mechanisms, should any entry points be exposed or introduced.

Key Concerns

  • Zero capability checks present
  • Zero nonce checks present
  • 1 medium severity CVE in history
Vulnerabilities
1

Easy MLS Listings Import Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-12525medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Easy MLS Listings Import <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Feb 17, 2025 Patched in 2.1.0 (3d)
Code Analysis
Analyzed Mar 16, 2026

Easy MLS Listings Import Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
11 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped11 total outputs
Attack Surface

Easy MLS Listings Import Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionplugins_loadedincludes\class-homeasap-featured-listings.php:142
actionadmin_menuincludes\class-homeasap-featured-listings.php:157
actionadmin_enqueue_scriptsincludes\class-homeasap-featured-listings.php:159
actionadmin_enqueue_scriptsincludes\class-homeasap-featured-listings.php:160
actionwp_enqueue_scriptsincludes\class-homeasap-featured-listings.php:175
actionwp_enqueue_scriptsincludes\class-homeasap-featured-listings.php:176
Maintenance & Trust

Easy MLS Listings Import Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 18, 2025
PHP min version7.4
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Easy MLS Listings Import Developer Profile

Home ASAP

2 plugins · 300 total installs

94
trust score
Avg Security Score
91/100
Avg Patch Time
6 days
View full developer profile
Detection Fingerprints

How We Detect Easy MLS Listings Import

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easy-mls-listings-import/admin/css/homeasap-featured-listings-admin.css/wp-content/plugins/easy-mls-listings-import/admin/js/homeasap-featured-listings-admin.js
Script Paths
/wp-content/plugins/easy-mls-listings-import/admin/js/homeasap-featured-listings-admin.js
Version Parameters
homeasap-featured-listings-admin.css?ver=homeasap-featured-listings-admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Easy MLS Listings Import