
HivePress Claim Listings Security & Risk Analysis
wordpress.org/plugins/hivepress-claim-listingsCharge users for claiming listings.
Is HivePress Claim Listings Safe to Use in 2026?
Mostly Safe
Score 77/100HivePress Claim Listings is generally safe to use. 2 past CVEs were resolved. Keep it updated.
The static analysis of hivepress-claim-listings v1.1.4 reveals a generally strong security posture with no identified dangerous functions, SQL injection vulnerabilities, or unescaped output. The absence of file operations and external HTTP requests is also a positive sign. However, the complete lack of detected AJAX handlers, REST API routes, shortcodes, cron events, and nonce checks within the analyzed attack surface is unusual and could indicate either an extremely minimal plugin or a limitation in the static analysis itself. The presence of only two capability checks suggests a potentially limited scope of access control implementation.
The vulnerability history presents a significant concern. With two known CVEs, and one currently unpatched, both classified as medium severity, this indicates a recurring pattern of security weaknesses. The common vulnerability type being 'Missing Authorization' directly contradicts the static analysis's indication of some capability checks, suggesting that the implemented checks may be insufficient or flawed in practice. The last vulnerability being so recent further amplifies the risk.
In conclusion, while the code itself appears to follow some good practices, the unpatched medium severity vulnerability and the historical pattern of missing authorization are critical red flags. The limited attack surface identified statically is a positive, but the potential for undiscovered vulnerabilities due to the historical issues warrants a high level of caution. The plugin's security is compromised by its past issues, despite some seemingly good static analysis results.
Key Concerns
- Unpatched medium severity vulnerability (1)
- Two known CVEs
- Common vulnerability type: Missing Authorization
- Lack of nonce checks
- Limited capability checks (2)
HivePress Claim Listings Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
HivePress Claim Listings <= 1.1.3 - Missing Authorization
HivePress Claim Listings <= 1.1.3 - Missing Authorization
HivePress Claim Listings Code Analysis
Output Escaping
HivePress Claim Listings Attack Surface
WordPress Hooks 12
Maintenance & Trust
HivePress Claim Listings Maintenance & Trust
Maintenance Signals
Community Trust
HivePress Claim Listings Alternatives
HivePress Favorites
hivepress-favorites
Allow users to keep a list of favorite listings.
HivePress Messages
hivepress-messages
Allow users to send private messages.
HivePress Reviews
hivepress-reviews
Allow users to rate and review listings.
HivePress Geolocation
hivepress-geolocation
Allow users to search listings by location.
HivePress Paid Listings
hivepress-paid-listings
Charge users for adding, featuring and renewing listings.
HivePress Claim Listings Developer Profile
9 plugins · 60K total installs
How We Detect HivePress Claim Listings
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hivepress-claim-listings/assets/css/claim-listing.css/wp-content/plugins/hivepress-claim-listings/assets/js/claim-listing.js/wp-content/plugins/hivepress-claim-listings/assets/js/claim-listing.jshivepress-claim-listings/assets/css/claim-listing.css?ver=hivepress-claim-listings/assets/js/claim-listing.js?ver=HTML / DOM Fingerprints
hp-listing-claim-buttonhp-listing-claim-formhp-listing-claim-detailsdata-listing-iddata-claim-idhivepresshp_claim_listing_params/wp-json/hivepress/v1/listing_claim