
ERE Recently Viewed – Essential Real Estate Add-On Security & Risk Analysis
wordpress.org/plugins/ere-recently-viewedERE Recently Viewed - Essential Real Estate Add-On shows properties viewed by a visitor as a responsive sidebar widget or in post/page using shortcode
Is ERE Recently Viewed – Essential Real Estate Add-On Safe to Use in 2026?
Generally Safe
Score 90/100ERE Recently Viewed – Essential Real Estate Add-On has a strong security track record. Known vulnerabilities have been patched promptly.
The ere-recently-viewed plugin v2.1 exhibits a mixed security posture. On one hand, the static analysis reveals a small attack surface with only one shortcode and no AJAX handlers or REST API routes. Furthermore, the code demonstrates good practices by using prepared statements for all SQL queries and having a high percentage of properly escaped output. There are no indications of dangerous functions, file operations, or external HTTP requests, which are positive signs.
However, significant concerns arise from the vulnerability history. The presence of a past critical vulnerability, specifically deserialization of untrusted data, is a major red flag. While this vulnerability is currently patched, it highlights a historical weakness in handling serialized data, which can be a complex and dangerous area if not managed meticulously. The lack of nonce checks and capability checks in the static analysis, although on a limited attack surface, means that any new vulnerabilities introduced in future versions could be more easily exploited if they involve actions that should be protected.
In conclusion, while the current version of the plugin shows some good coding practices, the history of a critical deserialization vulnerability warrants caution. The absence of nonce and capability checks on the identified entry points is a potential oversight that could be exploited if new vulnerabilities emerge. Users should remain vigilant for future updates and advisories.
Key Concerns
- History of critical vulnerability (Deserialization)
- Missing nonce checks
- Missing capability checks
- Some unescaped output
ERE Recently Viewed – Essential Real Estate Add-On Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
ERE Recently Viewed <= 1.3 - Unauthenticated PHP Object Injection
ERE Recently Viewed – Essential Real Estate Add-On Code Analysis
Output Escaping
ERE Recently Viewed – Essential Real Estate Add-On Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
ERE Recently Viewed – Essential Real Estate Add-On Maintenance & Trust
Maintenance Signals
Community Trust
ERE Recently Viewed – Essential Real Estate Add-On Alternatives
ERE Colors – Essential Real Estate Add-On
ere-colors
ERE Colors - Essential Real Estate Add-On is the most efficient way to re-color your real estate website. It provides 3 color pickers: Accent Color, C …
ERE Similar Properties – Essential Real Estate Add-On
ere-similar-properties
ERE Similar Properties displays a list of properties that are similar or related to the current property listing
ERE Download Document
ere-download-document
ERE Download Document use for collect name and email of customer before download attachment.
Essential Real Estate
essential-real-estate
Completely plugins Real Estate. Management system which allows you to own and maintain a real estate marketplace, intro website.
Property Hive
propertyhive
Building a property website? Property Hive has everything you need to get started, and so much more.
ERE Recently Viewed – Essential Real Estate Add-On Developer Profile
8 plugins · 19K total installs
How We Detect ERE Recently Viewed – Essential Real Estate Add-On
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ere-recently-viewed/assets/css/ere-recently-viewed.css/wp-content/plugins/ere-recently-viewed/assets/js/ere-recently-viewed.js/wp-content/plugins/ere-recently-viewed/assets/js/ere-recently-viewed.jsere-recently-viewed/assets/css/ere-recently-viewed.css?ver=ere-recently-viewed/assets/js/ere-recently-viewed.js?ver=HTML / DOM Fingerprints
ere-recently-viewed-wrapperdata-cookie-key="ere_recently_viewed_key"ERE_RV_AssetsERE_RV_Shortcode_Recently_ViewedERE_RV_Widget_Recently_Viewed