
immonex Kickstart Security & Risk Analysis
wordpress.org/plugins/immonex-kickstartEssential components and add-on framework for embedding and searching/filtering imported OpenImmo-XML-based real estate offers
Is immonex Kickstart Safe to Use in 2026?
Generally Safe
Score 98/100immonex Kickstart has a strong security track record. Known vulnerabilities have been patched promptly.
The "immonex-kickstart" v1.14.7 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a strong adherence to secure coding practices, with all SQL queries utilizing prepared statements and a good percentage of output being properly escaped. There are no identified file operations or external HTTP requests, and the number of entry points (shortcodes) is manageable and appear to have some level of authorization, as indicated by the presence of capability checks. Taint analysis also shows no critical or high-severity unsanitized flows, which is a very positive sign.
However, the presence of the `unserialize` function is a significant concern. While not directly flagged in taint analysis for this specific version, it's a known vector for remote code execution if not handled with extreme care, especially when dealing with user-supplied data. The absence of nonce checks on the identified entry points (shortcodes) is also a notable weakness, potentially opening the door to Cross-Site Request Forgery (CSRF) attacks if these shortcodes perform actions that can be triggered by unauthorized users.
The plugin's vulnerability history, particularly a past high-severity "PHP Remote File Inclusion" (RFI) vulnerability, is a red flag. Although there are no currently unpatched vulnerabilities, this historical pattern suggests that the plugin has had critical security flaws in the past. Developers should be vigilant about securing all input sources, especially those related to file operations or dynamic content loading, to prevent similar RFI issues from reoccurring. The overall security posture is decent due to strong SQL and output handling, but the potential risks from `unserialize` and the historical RFI vulnerability necessitate caution.
Key Concerns
- Dangerous function 'unserialize' present
- No nonce checks on entry points
- Past high severity RFI vulnerability
immonex Kickstart Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
immonex Kickstart <= 1.11.6 - Authenticated (Contributor+) Local File Inclusion
immonex Kickstart Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
immonex Kickstart Attack Surface
Shortcodes 8
WordPress Hooks 138
Maintenance & Trust
immonex Kickstart Maintenance & Trust
Maintenance Signals
Community Trust
immonex Kickstart Alternatives
immonex Kickstart Team
immonex-kickstart-team
immonex Kickstart add-on for handling, linking and embedding OpenImmo-XML-based real estate agent/agency information and contact forms
WP Immo Manager
wp-immo-manager
WP Immo Manager integriert Immobilien aus ihrer Makler-Software in Wordpress. OpenImmo Import ihrer Immobilien aus einer Immo-Verwaltungssoftware.
All-in-One WP Migration and Backup
all-in-one-wp-migration
Trusted by 60M+ sites: The gold standard for WordPress migration and backup. Migrate, backup, and restore your WordPress site with one click.
WordPress Importer
wordpress-importer
Import posts, pages, comments, custom fields, categories, tags and more from a WordPress export file.
One Click Demo Import
one-click-demo-import
Import your demo content, widgets and theme settings with one click. Theme authors! Enable simple theme demo import for your users.
immonex Kickstart Developer Profile
2 plugins · 400 total installs
How We Detect immonex Kickstart
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/immonex-kickstart/css/admin/meta.css/wp-content/plugins/immonex-kickstart/css/admin/styles.css/wp-content/plugins/immonex-kickstart/css/frontend/gallery-slider.css/wp-content/plugins/immonex-kickstart/css/frontend/immonex-kickstart.css/wp-content/plugins/immonex-kickstart/css/frontend/map-styles.css/wp-content/plugins/immonex-kickstart/css/frontend/property-list.css/wp-content/plugins/immonex-kickstart/css/frontend/property-search.css/wp-content/plugins/immonex-kickstart/css/frontend/property-view.css+15 moreimmonex Kickstart/wp-content/plugins/immonex-kickstart/js/admin/editor-extensions.js/wp-content/plugins/immonex-kickstart/js/admin/meta.js/wp-content/plugins/immonex-kickstart/js/admin/settings.js/wp-content/plugins/immonex-kickstart/js/frontend/gallery-slider.js/wp-content/plugins/immonex-kickstart/js/frontend/inline-styles.js/wp-content/plugins/immonex-kickstart/js/frontend/map-init.js+7 moreimmonex-kickstart/css/admin/meta.css?ver=immonex-kickstart/css/admin/styles.css?ver=immonex-kickstart/css/frontend/gallery-slider.css?ver=immonex-kickstart/css/frontend/immonex-kickstart.css?ver=immonex-kickstart/css/frontend/map-styles.css?ver=immonex-kickstart/css/frontend/property-list.css?ver=immonex-kickstart/css/frontend/property-search.css?ver=immonex-kickstart/css/frontend/property-view.css?ver=immonex-kickstart/css/frontend/share-buttons.css?ver=immonex-kickstart/css/frontend/slider.css?ver=immonex-kickstart/js/admin/editor-extensions.js?ver=immonex-kickstart/js/admin/meta.js?ver=immonex-kickstart/js/admin/settings.js?ver=immonex-kickstart/js/frontend/gallery-slider.js?ver=immonex-kickstart/js/frontend/inline-styles.js?ver=immonex-kickstart/js/frontend/map-init.js?ver=immonex-kickstart/js/frontend/property-list.js?ver=immonex-kickstart/js/frontend/property-search.js?ver=immonex-kickstart/js/frontend/property-view.js?ver=immonex-kickstart/js/frontend/share-buttons.js?ver=immonex-kickstart/js/frontend/slider.js?ver=immonex-kickstart/js/frontend/sticky-element.js?ver=immonex-kickstart/js/frontend/virtual-tour-init.js?ver=HTML / DOM Fingerprints
inx-gallery-sliderinx-gallery-thumb-containerinx-gallery-thumb-wrapperinx-gallery-main-image-containerinx-gallery-main-image-wrapperinx-gallery-image-loaderinx-gallery-image-nav-buttoninx-gallery-slide-nav-button+20 more<!-- Begin: immonex_kickstart: Gallery Slider --><!-- End: immonex_kickstart: Gallery Slider --><!-- Begin: immonex_kickstart: Map --><!-- End: immonex_kickstart: Map -->+12 moredata-inx-property-iddata-inx-gallery-imagesdata-inx-gallery-settingsdata-inx-map-latdata-inx-map-lngdata-inx-map-zoom+3 morewindow.inxGallerySliderwindow.inxMapInitwindow.inxPropertySearchwindow.inxShareButtonswindow.inxSlider[immonex_kickstart_gallery][immonex_kickstart_map][immonex_kickstart_property_list][immonex_kickstart_property_search]