Garagem Security & Risk Analysis

wordpress.org/plugins/garagem

Integre seu site WordPress com o Garagem CRM. Exiba imóveis sincronizados, com busca, filtros e captação de leads — tudo automático.

0 active installs v1.0.1 PHP 7.4+ WP 6.0+ Updated Mar 20, 2026
crmproperty-managementreal-estaterealtorwhatsapp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Garagem Safe to Use in 2026?

Generally Safe

Score 100/100

Garagem has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'garagem' plugin v1.0.1 exhibits a strong security posture based on the provided static analysis. The code demonstrates good practices by effectively utilizing prepared statements for all SQL queries and maintaining a high rate of proper output escaping, with only a negligible percentage potentially unescaped. The absence of dangerous functions, file operations, and known vulnerability history is highly positive. Furthermore, all identified entry points (AJAX handlers and shortcodes) appear to have appropriate authentication and permission checks in place, indicating a deliberate effort to secure these functionalities. The plugin also implements nonce and capability checks, which are crucial for preventing various types of attacks.

Despite these strengths, a few areas warrant attention. The plugin makes four external HTTP requests, which could be a vector for supply chain attacks or information disclosure if not handled securely. While the taint analysis reported zero flows, this may be due to the analysis depth or the absence of complex data manipulation within the plugin. The lack of any recorded vulnerabilities in its history, while generally positive, could also indicate a less mature plugin that hasn't been subjected to extensive real-world testing or red-teaming.

In conclusion, 'garagem' v1.0.1 presents a relatively secure profile with commendable adherence to secure coding principles for SQL and output handling, along with protected entry points. The primary concern lies with the external HTTP requests, which should be monitored and secured. The absence of past vulnerabilities and zero taint flows are good indicators, but a comprehensive security assessment would benefit from deeper taint analysis and ongoing monitoring for potential undiscovered weaknesses.

Key Concerns

  • External HTTP requests present
Vulnerabilities
None known

Garagem Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Garagem Release Timeline

v1.0.1Current
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Garagem Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
3 prepared
Unescaped Output
3
293 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
4
Bundled Libraries
0

SQL Query Safety

100% prepared3 total queries

Output Escaping

99% escaped296 total outputs
Attack Surface

Garagem Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 1

authwp_ajax_garagem_clear_cacheincludes/class-garagem-admin.php:24

Shortcodes 2

[garagem_property] includes/class-garagem-shortcodes.php:45
[garagem_search] includes/class-garagem-shortcodes.php:46
WordPress Hooks 14
actionwp_enqueue_scriptsgaragem-properties.php:150
actionwp_headgaragem-properties.php:336
filterlanguage_attributesgaragem-properties.php:347
actioninitgaragem-properties.php:379
filterquery_varsgaragem-properties.php:388
filtertemplate_includegaragem-properties.php:403
actiontemplate_redirectgaragem-properties.php:462
actionupdate_option_garagem_property_pagesgaragem-properties.php:475
actionupdate_option_garagem_property_base_pagegaragem-properties.php:476
actionadmin_menuincludes/class-garagem-admin.php:22
actionadmin_initincludes/class-garagem-admin.php:23
actionadmin_enqueue_scriptsincludes/class-garagem-admin.php:25
filterpre_get_document_titleincludes/class-garagem-seo.php:98
actionwp_headincludes/class-garagem-seo.php:101
Maintenance & Trust

Garagem Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 20, 2026
PHP min version7.4
Downloads191

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Garagem Developer Profile

Garagem

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Garagem

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/garagem/assets/css/garagem-properties.min.css/wp-content/plugins/garagem/src/css/garagem-properties.css/wp-content/plugins/garagem/assets/js/garagem-properties.bundle.min.js/wp-content/plugins/garagem/src/js/garagem-api.js/wp-content/plugins/garagem/src/js/garagem-url-handler.js/wp-content/plugins/garagem/src/js/garagem-utils.js/wp-content/plugins/garagem/src/js/garagem-drawer.js/wp-content/plugins/garagem/src/js/garagem-gallery.js+5 more
Script Paths
/wp-content/plugins/garagem/assets/js/garagem-properties.bundle.min.js/wp-content/plugins/garagem/src/js/garagem-api.js/wp-content/plugins/garagem/src/js/garagem-url-handler.js/wp-content/plugins/garagem/src/js/garagem-utils.js/wp-content/plugins/garagem/src/js/garagem-drawer.js/wp-content/plugins/garagem/src/js/garagem-gallery.js+5 more
Version Parameters
ver=ver=ver=ver=ver=ver=ver=ver=ver=ver=ver=ver=

HTML / DOM Fingerprints

Data Attributes
data-garagem-site-iddata-garagem-api-basedata-garagem-items-per-pagedata-garagem-primary-colordata-garagem-new-tabdata-garagem-loading-text+18 more
JS Globals
garagemConfig
FAQ

Frequently Asked Questions about Garagem