HivePress Claim Listings Security & Risk Analysis

wordpress.org/plugins/hivepress-claim-listings

Charge users for claiming listings.

3K active installs v1.1.4 PHP 7.4+ WP 5.0+ Updated Jan 30, 2026
claim-listingsclassifiedsdirectoryhivepresslistings
77
B · Generally Safe
CVEs total2
Unpatched1
Last CVESep 26, 2025
Download
Safety Verdict

Is HivePress Claim Listings Safe to Use in 2026?

Mostly Safe

Score 77/100

HivePress Claim Listings is generally safe to use. 2 past CVEs were resolved. Keep it updated.

2 known CVEs 1 unpatched Last CVE: Sep 26, 2025Updated 2mo ago
Risk Assessment

The static analysis of hivepress-claim-listings v1.1.4 reveals a generally strong security posture with no identified dangerous functions, SQL injection vulnerabilities, or unescaped output. The absence of file operations and external HTTP requests is also a positive sign. However, the complete lack of detected AJAX handlers, REST API routes, shortcodes, cron events, and nonce checks within the analyzed attack surface is unusual and could indicate either an extremely minimal plugin or a limitation in the static analysis itself. The presence of only two capability checks suggests a potentially limited scope of access control implementation.

The vulnerability history presents a significant concern. With two known CVEs, and one currently unpatched, both classified as medium severity, this indicates a recurring pattern of security weaknesses. The common vulnerability type being 'Missing Authorization' directly contradicts the static analysis's indication of some capability checks, suggesting that the implemented checks may be insufficient or flawed in practice. The last vulnerability being so recent further amplifies the risk.

In conclusion, while the code itself appears to follow some good practices, the unpatched medium severity vulnerability and the historical pattern of missing authorization are critical red flags. The limited attack surface identified statically is a positive, but the potential for undiscovered vulnerabilities due to the historical issues warrants a high level of caution. The plugin's security is compromised by its past issues, despite some seemingly good static analysis results.

Key Concerns

  • Unpatched medium severity vulnerability (1)
  • Two known CVEs
  • Common vulnerability type: Missing Authorization
  • Lack of nonce checks
  • Limited capability checks (2)
Vulnerabilities
2

HivePress Claim Listings Security Vulnerabilities

CVEs by Year

2 CVEs in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-60122medium · 4.3Missing Authorization

HivePress Claim Listings <= 1.1.3 - Missing Authorization

Sep 26, 2025Unpatched
CVE-2025-60123medium · 4.3Missing Authorization

HivePress Claim Listings <= 1.1.3 - Missing Authorization

Sep 26, 2025 Patched in 1.1.4 (154d)
Code Analysis
Analyzed Mar 16, 2026

HivePress Claim Listings Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
20 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped20 total outputs
Attack Surface

HivePress Claim Listings Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
filterhivepress/v1/extensionshivepress-claim-listings.php:18
filterhivepress/v1/models/listing_claim/errorsincludes\components\class-listing-claim.php:32
actionhivepress/v1/models/listing_claim/createincludes\components\class-listing-claim.php:35
actionhivepress/v1/models/listing_claim/updateincludes\components\class-listing-claim.php:36
actionhivepress/v1/models/listing_claim/update_statusincludes\components\class-listing-claim.php:39
actionwoocommerce_order_status_changedincludes\components\class-listing-claim.php:44
actiontemplate_redirectincludes\components\class-listing-claim.php:47
filtermanage_hp_listing_claim_posts_columnsincludes\components\class-listing-claim.php:53
actionmanage_hp_listing_claim_posts_custom_columnincludes\components\class-listing-claim.php:54
filterhivepress/v1/meta_boxes/listing_claim_settingsincludes\components\class-listing-claim.php:57
filterhivepress/v1/forms/listing_claim_submitincludes\components\class-listing-claim.php:61
filterhivepress/v1/templates/listing_view_page/blocksincludes\components\class-listing-claim.php:64
Maintenance & Trust

HivePress Claim Listings Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 30, 2026
PHP min version7.4
Downloads46K

Community Trust

Rating100/100
Number of ratings1
Active installs3K
Developer Profile

HivePress Claim Listings Developer Profile

HivePress

9 plugins · 60K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
154 days
View full developer profile
Detection Fingerprints

How We Detect HivePress Claim Listings

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hivepress-claim-listings/assets/css/claim-listing.css/wp-content/plugins/hivepress-claim-listings/assets/js/claim-listing.js
Script Paths
/wp-content/plugins/hivepress-claim-listings/assets/js/claim-listing.js
Version Parameters
hivepress-claim-listings/assets/css/claim-listing.css?ver=hivepress-claim-listings/assets/js/claim-listing.js?ver=

HTML / DOM Fingerprints

CSS Classes
hp-listing-claim-buttonhp-listing-claim-formhp-listing-claim-details
Data Attributes
data-listing-iddata-claim-id
JS Globals
hivepresshp_claim_listing_params
REST Endpoints
/wp-json/hivepress/v1/listing_claim
FAQ

Frequently Asked Questions about HivePress Claim Listings