
Grundly – Immobilienbewertung und Wertermittlung für Makler Security & Risk Analysis
wordpress.org/plugins/grundly-immobilienbewertung-wertermittlung-fuer-maklerProperty valuation lead generator for real estate agents. Add the Grundly widget with shortcode and collect homeowner leads in minutes.
Is Grundly – Immobilienbewertung und Wertermittlung für Makler Safe to Use in 2026?
Generally Safe
Score 100/100Grundly – Immobilienbewertung und Wertermittlung für Makler has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "grundly-immobilienbewertung-wertermittlung-fuer-makler" v1.0.2 reveals a generally positive security posture. The absence of any entry points like AJAX handlers, REST API routes, or shortcodes, combined with zero critical or high-severity taint flows, suggests a well-contained plugin. The use of prepared statements for all SQL queries is a significant strength, mitigating common SQL injection risks. Furthermore, the plugin demonstrates good practices by incorporating capability checks and avoiding file operations or external HTTP requests.
However, a notable concern is the relatively low percentage of properly escaped output (45%). This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, particularly if user-supplied data is directly outputted without sufficient sanitization. The lack of nonce checks on any entry points, while less critical given the absence of such points, is a missed opportunity for robust security if the attack surface were to expand in future versions. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive sign, but it's important to remember that absence of evidence is not evidence of absence, especially for less popular plugins.
In conclusion, "grundly-immobilienbewertung-wertermittlung-fuer-makler" v1.0.2 exhibits a strong foundation in secure coding practices, particularly regarding data handling and the attack surface. The primary area for improvement lies in ensuring consistent and robust output escaping to prevent potential XSS vulnerabilities.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks on entry points
Grundly – Immobilienbewertung und Wertermittlung für Makler Security Vulnerabilities
Grundly – Immobilienbewertung und Wertermittlung für Makler Code Analysis
Output Escaping
Grundly – Immobilienbewertung und Wertermittlung für Makler Attack Surface
WordPress Hooks 4
Maintenance & Trust
Grundly – Immobilienbewertung und Wertermittlung für Makler Maintenance & Trust
Maintenance Signals
Community Trust
Grundly – Immobilienbewertung und Wertermittlung für Makler Alternatives
Free Property Valuation (Lead Generator) / Kostenlose Immobilienbewertung
kostenlose-immobilienbewertung-lead-generator
Generate leads with free real estate valuations - for realtors and advertising agencies
immonex Kickstart Team
immonex-kickstart-team
immonex Kickstart add-on for handling, linking and embedding OpenImmo-XML-based real estate agent/agency information and contact forms
immonex Kickstart
immonex-kickstart
Essential components and add-on framework for embedding and searching/filtering imported OpenImmo-XML-based real estate offers
WP Immo Manager
wp-immo-manager
WP Immo Manager integriert Immobilien aus ihrer Makler-Software in Wordpress. OpenImmo Import ihrer Immobilien aus einer Immo-Verwaltungssoftware.
Immocaster WordPress Plugin
immocaster
Das Wordpress Plugin von Immocaster ermöglicht die Anzeige von Immobilien von ImmobilienScout24 im eingehen Blog.
Grundly – Immobilienbewertung und Wertermittlung für Makler Developer Profile
1 plugin · 0 total installs
How We Detect Grundly – Immobilienbewertung und Wertermittlung für Makler
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/grundly-immobilienbewertung-wertermittlung-fuer-makler/assets/admin.jshttps://grundly.de/widget.jsgrundly-immobilienbewertung-wertermittlung-fuer-makler/assets/admin.js?ver=1.0.2HTML / DOM Fingerprints
data-makler-iddata-widget-iddata-integration-sourcegrundly_widget_embed_config[grundly][grundly_widget]