
Immocaster WordPress Plugin Security & Risk Analysis
wordpress.org/plugins/immocasterDas Wordpress Plugin von Immocaster ermöglicht die Anzeige von Immobilien von ImmobilienScout24 im eingehen Blog.
Is Immocaster WordPress Plugin Safe to Use in 2026?
Use With Caution
Score 61/100Immocaster WordPress Plugin has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The immocaster v1.3.6 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and performing nonce checks. The absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points is also a strong indicator of a reduced attack surface. However, the static analysis reveals significant concerns, most notably that only 9% of its 81 outputs are properly escaped, leaving a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. Additionally, the presence of two unsanitized taint flows, though not classified as critical or high severity in this analysis, warrants further investigation as these can often lead to exploitable conditions. The vulnerability history is a major red flag, with one high-severity "PHP Remote File Inclusion" vulnerability that is currently unpatched. This historical pattern of severe vulnerabilities, especially the recurring RFI type, suggests a recurring weakness in how external data or files are handled within the plugin.
While the plugin has strengths in its minimal attack surface and SQL query handling, the critical issues of poor output escaping and a recent, unpatched RFI vulnerability present a substantial risk. The historical pattern of RFI vulnerabilities is particularly concerning, as it indicates a persistent flaw that could be exploited again. Therefore, users of immocaster v1.3.6 should exercise extreme caution. The unpatched RFI vulnerability alone is a critical risk that needs immediate attention, and the widespread lack of output escaping increases the overall exposure to other common web vulnerabilities.
Key Concerns
- Unpatched high severity CVE
- Low output escaping percentage (9%)
- Unsanitized taint flows (2)
Immocaster WordPress Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Immocaster WordPress <= 1.3.6 - Unauthenticated Local File Inclusion
Immocaster WordPress Plugin Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Immocaster WordPress Plugin Attack Surface
WordPress Hooks 18
Maintenance & Trust
Immocaster WordPress Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Immocaster WordPress Plugin Alternatives
immonex Kickstart
immonex-kickstart
Essential components and add-on framework for embedding and searching/filtering imported OpenImmo-XML-based real estate offers
immonex Kickstart Team
immonex-kickstart-team
immonex Kickstart add-on for handling, linking and embedding OpenImmo-XML-based real estate agent/agency information and contact forms
Free Property Valuation (Lead Generator) / Kostenlose Immobilienbewertung
kostenlose-immobilienbewertung-lead-generator
Generate leads with free real estate valuations - for realtors and advertising agencies
WP Immo Manager
wp-immo-manager
WP Immo Manager integriert Immobilien aus ihrer Makler-Software in Wordpress. OpenImmo Import ihrer Immobilien aus einer Immo-Verwaltungssoftware.
ImmoWP Gestion Immobiliere
immowp-gestion-immobiliere
Plugin complet de gestion immobilière pour WordPress. Créez un site d'agence professionnel avec synchronisation automatique disponible.
Immocaster WordPress Plugin Developer Profile
1 plugin · 10 total installs
How We Detect Immocaster WordPress Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/immocaster/lib/galleria/galleria-1.2.6.wp-version.min.js/wp-content/plugins/immocaster/js/ajax.js/wp-content/plugins/immocaster/lib/jquery-ui/css/smoothness/jquery-ui-1.10.0.custom.min.css/wp-content/plugins/immocaster/css/admin.css/wp-content/plugins/immocaster/custom/css/style.css/wp-content/plugins/immocaster/default/css/style.csslib/galleria/galleria-1.2.6.wp-version.min.jsjs/ajax.jsimmocaster/lib/galleria/galleria-1.2.6.wp-version.min.js?ver=immocaster/js/ajax.js?ver=immocaster/lib/jquery-ui/css/smoothness/jquery-ui-1.10.0.custom.min.css?ver=immocaster/css/admin.css?ver=immocaster/custom/css/style.css?ver=immocaster/default/css/style.css?ver=HTML / DOM Fingerprints
immocaster_mb_resultlist_regionimmocaster_mb_resultlist_all_regionsimmocaster_ajax