IDXPro Security & Risk Analysis

wordpress.org/plugins/idxpro

IDXPro is an MLS Search Application. It's designed to blend seamlessly into your website. Try it for free!

10 active installs v1.4.3 PHP + WP 3.0+ Updated Sep 5, 2014
idxidx-searchidxpromlsmls-search
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is IDXPro Safe to Use in 2026?

Generally Safe

Score 85/100

IDXPro has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The idxpro v1.4.3 plugin demonstrates several positive security practices, including the complete absence of recorded CVEs and the exclusive use of prepared statements for SQL queries. It also incorporates nonce and capability checks, and appears to have a limited attack surface with no identified unprotected entry points. However, significant concerns arise from the static code analysis. The presence of the `unserialize` function, especially without clear sanitization context provided, is a known risk for object injection vulnerabilities if user-controlled data is passed to it. Furthermore, 0% of the 25 identified output operations are properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The two taint flows identified with unsanitized paths further amplify these concerns, suggesting potential for malicious data to be processed without adequate cleaning. While the vulnerability history is clean, this can be misleading if the plugin hasn't been subjected to thorough, ongoing security audits or if potential vulnerabilities like XSS and unserialize issues have simply gone unnoticed or unreported. The strengths in SQL handling and overall entry point protection are overshadowed by the critical risks associated with unescaped output and the potential for object injection via `unserialize`.

Key Concerns

  • Unescaped output (25/25)
  • Dangerous function: unserialize used
  • Taint flows with unsanitized paths (2)
Vulnerabilities
None known

IDXPro Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

IDXPro Release Timeline

v1.4.3Current
v1.4.2
v1.4.1
v1.4
v1.3
Code Analysis
Analyzed Apr 16, 2026

IDXPro Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
25
0 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
1
Bundled Libraries
1

Dangerous Functions Found

unserialize$idxpro_account = unserialize($idxpro_account_check['body']);idxpro.php:156

Bundled Libraries

TinyMCE

Output Escaping

0% escaped25 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
idxpro_conf (admin.php:100)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

IDXPro Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[idxpro] idxpro.php:435
WordPress Hooks 10
actionadmin_noticesadmin.php:31
actionadmin_initadmin.php:38
actionadmin_menuadmin.php:56
filterplugin_action_linksadmin.php:95
actionadmin_noticesadmin.php:419
filtermce_external_pluginstinymce/tinymce.php:19
filtermce_buttonstinymce/tinymce.php:20
actioninittinymce/tinymce.php:23
filtertiny_mce_versiontinymce/tinymce.php:75
actionplugins_loadedwidget.php:23
Maintenance & Trust

IDXPro Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedSep 5, 2014
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

IDXPro Developer Profile

ihouse IDXPro Development

2 plugins · 10 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect IDXPro

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/idxpro/idxpro-styles.css/wp-content/plugins/idxpro/idxpro-scripts.js
Script Paths
/wp-content/plugins/idxpro/idxpro-scripts.js
Version Parameters
idxpro-styles.css?ver=idxpro-scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
idxpro-widget
Data Attributes
data-idxpro-id
JS Globals
idxpro_settings
Shortcode Output
[idxpro-widget[idxpro-widget]
FAQ

Frequently Asked Questions about IDXPro