
Houzez Property Feed Security & Risk Analysis
wordpress.org/plugins/houzez-property-feedAutomatically import properties to Houzez from estate agency CRMs and export to portals
Is Houzez Property Feed Safe to Use in 2026?
Generally Safe
Score 98/100Houzez Property Feed has a strong security track record. Known vulnerabilities have been patched promptly.
The houzez-property-feed v2.5.42 plugin exhibits a mixed security posture. While it demonstrates some good security practices such as a high percentage of SQL queries using prepared statements and a substantial number of output escaping routines, significant concerns remain. The presence of 8 AJAX handlers, with a concerning 3 lacking authentication checks, presents a direct attack vector. Furthermore, 27 out of 43 analyzed data flows had unsanitized paths, with 12 flagged as high severity, indicating potential risks such as path traversal or injection vulnerabilities that could be exploited by an attacker.
The plugin's vulnerability history, with 2 known CVEs including a past high-severity path traversal and CSRF vulnerability, suggests a recurring pattern of exploitable weaknesses. Although there are currently no unpatched vulnerabilities, the historical prevalence of these types of issues, coupled with the static analysis findings of unsanitized paths and insecure AJAX endpoints, warrants caution. The plugin has several strengths in terms of secure coding practices like prepared statements and output escaping, but the identified vulnerabilities and critical data flow issues create a notable risk profile that requires attention.
Key Concerns
- 3 unprotected AJAX handlers
- 12 high severity taint flows (unsanitized paths)
- History of Path Traversal vulnerability
- History of CSRF vulnerability
- 27 flows with unsanitized paths
- Only 1 capability check identified
- 2 dangerous functions (exec, unserialize)
Houzez Property Feed Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Houzez Property Feed <= 2.5.4 - Unauthenticated Arbitrary File Download
Houzez Property Feed <= 2.4.21 - Cross-Site Request Forgery to Property Feed Export Deletion
Houzez Property Feed Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Houzez Property Feed Attack Surface
AJAX Handlers 8
WordPress Hooks 64
Scheduled Events 6
Maintenance & Trust
Houzez Property Feed Maintenance & Trust
Maintenance Signals
Community Trust
Houzez Property Feed Alternatives
Realtivo-Resales Online for Houzez
realtivo-resales-online-for-houzez
Connect the Houzez theme with Resales Online to import live property listings. Easy setup. No coding. Free to use.
Property Hive
propertyhive
Building a property website? Property Hive has everything you need to get started, and so much more.
Estatik Real Estate Plugin
estatik
You will love its clean design, simple use, and colorful themes. WordPress real estate plugin Estatik is a worthy choice for single agents and portals
WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress
wpvr
Create stunning 360 virtual tours to impress visitors and get more clients using WPVR - the easiest virtual tour creator in WordPress.
Essential Real Estate
essential-real-estate
Completely plugins Real Estate. Management system which allows you to own and maintain a real estate marketplace, intro website.
Houzez Property Feed Developer Profile
8 plugins · 7K total installs
How We Detect Houzez Property Feed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/houzez-property-feed/admin/css/houzez-property-feed-admin.css/wp-content/plugins/houzez-property-feed/admin/js/houzez-property-feed-admin.js/wp-content/plugins/houzez-property-feed/includes/css/jquery.fileuploader.css/wp-content/plugins/houzez-property-feed/includes/js/jquery.fileuploader.min.js/wp-content/plugins/houzez-property-feed/includes/js/houzez-property-feed-main.js/wp-content/plugins/houzez-property-feed/includes/js/houzez-property-feed-settings.js/wp-content/plugins/houzez-property-feed/includes/js/houzez-property-feed-import.jsadmin/js/houzez-property-feed-admin.jsincludes/js/jquery.fileuploader.min.jsincludes/js/houzez-property-feed-main.jsincludes/js/houzez-property-feed-settings.jsincludes/js/houzez-property-feed-import.jshouzez-property-feed/admin/css/houzez-property-feed-admin.css?ver=houzez-property-feed/admin/js/houzez-property-feed-admin.js?ver=houzez-property-feed/includes/css/jquery.fileuploader.css?ver=houzez-property-feed/includes/js/jquery.fileuploader.min.js?ver=houzez-property-feed/includes/js/houzez-property-feed-main.js?ver=houzez-property-feed/includes/js/houzez-property-feed-settings.js?ver=houzez-property-feed/includes/js/houzez-property-feed-import.js?ver=HTML / DOM Fingerprints
hpf-upload-file-wraphpf-fileuploaderhpf-upload-btnhpf-import-settingshpf-import-wrapperhouzez-property-feed-settings<!-- Houzez Property Feed --><!-- HOUZEZ PROPERTY FEED IMPORT SECTION --><!-- HOUZEZ PROPERTY FEED EXPORT SECTION -->data-hpf-feed-iddata-hpf-feed-slughouzez_property_feed_paramshouzez_property_feed_settings_paramshouzez_property_feed_import_params/wp-json/hpf/v1/get-feeds/wp-json/hpf/v1/save-feed/wp-json/hpf/v1/delete-feed/wp-json/hpf/v1/import-feed