ERE Recently Viewed – Essential Real Estate Add-On Security & Risk Analysis

wordpress.org/plugins/ere-recently-viewed

ERE Recently Viewed - Essential Real Estate Add-On shows properties viewed by a visitor as a responsive sidebar widget or in post/page using shortcode

1K active installs v2.1 PHP + WP 4.5+ Updated Jul 23, 2024
agencyagentessential-real-estatepropertyreal-estate
90
A · Safe
CVEs total1
Unpatched0
Last CVEJan 31, 2024
Safety Verdict

Is ERE Recently Viewed – Essential Real Estate Add-On Safe to Use in 2026?

Generally Safe

Score 90/100

ERE Recently Viewed – Essential Real Estate Add-On has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 31, 2024Updated 1yr ago
Risk Assessment

The ere-recently-viewed plugin v2.1 exhibits a mixed security posture. On one hand, the static analysis reveals a small attack surface with only one shortcode and no AJAX handlers or REST API routes. Furthermore, the code demonstrates good practices by using prepared statements for all SQL queries and having a high percentage of properly escaped output. There are no indications of dangerous functions, file operations, or external HTTP requests, which are positive signs.

However, significant concerns arise from the vulnerability history. The presence of a past critical vulnerability, specifically deserialization of untrusted data, is a major red flag. While this vulnerability is currently patched, it highlights a historical weakness in handling serialized data, which can be a complex and dangerous area if not managed meticulously. The lack of nonce checks and capability checks in the static analysis, although on a limited attack surface, means that any new vulnerabilities introduced in future versions could be more easily exploited if they involve actions that should be protected.

In conclusion, while the current version of the plugin shows some good coding practices, the history of a critical deserialization vulnerability warrants caution. The absence of nonce and capability checks on the identified entry points is a potential oversight that could be exploited if new vulnerabilities emerge. Users should remain vigilant for future updates and advisories.

Key Concerns

  • History of critical vulnerability (Deserialization)
  • Missing nonce checks
  • Missing capability checks
  • Some unescaped output
Vulnerabilities
1

ERE Recently Viewed – Essential Real Estate Add-On Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Critical
1

1 total CVE

CVE-2024-24797critical · 9.8Deserialization of Untrusted Data

ERE Recently Viewed <= 1.3 - Unauthenticated PHP Object Injection

Jan 31, 2024 Patched in 2.0 (27d)
Code Analysis
Analyzed Mar 16, 2026

ERE Recently Viewed – Essential Real Estate Add-On Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

75% escaped4 total outputs
Attack Surface

ERE Recently Viewed – Essential Real Estate Add-On Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[ere_recently_viewed] inc\shortcode-recently-viewed.class.php:19
WordPress Hooks 8
actionplugins_loadedere-recently-viewed.php:50
actionadmin_noticesere-recently-viewed.php:51
actionplugins_loadedere-recently-viewed.php:52
actionwidgets_initere-recently-viewed.php:75
actiontemplate_redirectere-recently-viewed.php:78
actioninitinc\assets.class.php:19
actionwp_enqueue_scriptsinc\assets.class.php:20
actionin_widget_forminc\shortcode-recently-viewed.class.php:18
Maintenance & Trust

ERE Recently Viewed – Essential Real Estate Add-On Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedJul 23, 2024
PHP min version
Downloads27K

Community Trust

Rating0/100
Number of ratings0
Active installs1K
Developer Profile

ERE Recently Viewed – Essential Real Estate Add-On Developer Profile

g5theme

8 plugins · 19K total installs

64
trust score
Avg Security Score
79/100
Avg Patch Time
157 days
View full developer profile
Detection Fingerprints

How We Detect ERE Recently Viewed – Essential Real Estate Add-On

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ere-recently-viewed/assets/css/ere-recently-viewed.css/wp-content/plugins/ere-recently-viewed/assets/js/ere-recently-viewed.js
Script Paths
/wp-content/plugins/ere-recently-viewed/assets/js/ere-recently-viewed.js
Version Parameters
ere-recently-viewed/assets/css/ere-recently-viewed.css?ver=ere-recently-viewed/assets/js/ere-recently-viewed.js?ver=

HTML / DOM Fingerprints

CSS Classes
ere-recently-viewed-wrapper
Data Attributes
data-cookie-key="ere_recently_viewed_key"
JS Globals
ERE_RV_AssetsERE_RV_Shortcode_Recently_ViewedERE_RV_Widget_Recently_Viewed
FAQ

Frequently Asked Questions about ERE Recently Viewed – Essential Real Estate Add-On