
immonex Kickstart Team Security & Risk Analysis
wordpress.org/plugins/immonex-kickstart-teamimmonex Kickstart add-on for handling, linking and embedding OpenImmo-XML-based real estate agent/agency information and contact forms
Is immonex Kickstart Team Safe to Use in 2026?
Generally Safe
Score 98/100immonex Kickstart Team has a strong security track record. Known vulnerabilities have been patched promptly.
The "immonex-kickstart-team" plugin version 1.8.3 demonstrates several positive security practices, including the exclusive use of prepared statements for SQL queries and the presence of capability checks and nonce checks. The static analysis shows a relatively small attack surface with no unprotected entry points (AJAX handlers, REST API routes). Taint analysis found no flows, indicating no obvious paths for untrusted data to reach sensitive operations. However, a significant concern arises from the vulnerability history, which lists a past high-severity "PHP Remote File Inclusion" (RFI) vulnerability. While currently unpatched CVEs are reported as zero, the nature of RFI vulnerabilities suggests a potential for severe compromise if similar weaknesses are reintroduced. The code also shows a low percentage of properly escaped output, which could lead to Cross-Site Scripting (XSS) vulnerabilities, especially if untrusted data is handled within these outputs. The presence of file operations without clear sanitization could also be a vector if not handled carefully.
In conclusion, while the plugin has strengths in its SQL handling and entry point protection, the historical RFI vulnerability and the high proportion of unescaped output are significant weaknesses that warrant careful consideration. The absence of RFI in the current analysis is positive, but the historical pattern combined with potential XSS vectors creates a moderate risk profile. Continued vigilance and thorough code reviews for any updates are recommended.
Key Concerns
- High severity RFI vulnerability in history
- Low percentage of properly escaped output
- Uncertainty regarding file operation sanitization
immonex Kickstart Team Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
immonex Kickstart Team <= 1.6.9 - Authenticated (Contributor+) Local File Inclusion
immonex Kickstart Team Code Analysis
SQL Query Safety
Output Escaping
immonex Kickstart Team Attack Surface
Shortcodes 3
WordPress Hooks 61
Maintenance & Trust
immonex Kickstart Team Maintenance & Trust
Maintenance Signals
Community Trust
immonex Kickstart Team Alternatives
immonex Kickstart
immonex-kickstart
Essential components and add-on framework for embedding and searching/filtering imported OpenImmo-XML-based real estate offers
WP Immo Manager
wp-immo-manager
WP Immo Manager integriert Immobilien aus ihrer Makler-Software in Wordpress. OpenImmo Import ihrer Immobilien aus einer Immo-Verwaltungssoftware.
Neptune Real Estate
neptune-real-estate
Free real estate plugin for WordPress that lets you create, manage and list properties
Grundly – Immobilienbewertung und Wertermittlung für Makler
grundly-immobilienbewertung-wertermittlung-fuer-makler
Property valuation lead generator for real estate agents. Add the Grundly widget with shortcode and collect homeowner leads in minutes.
ActiveCampaign – The autonomous marketing platform
activecampaign-subscription-forms
Add ActiveCampaign contact forms and live chat to any post, page, or sidebar. Also enable ActiveCampaign site tracking for your WordPress blog.
immonex Kickstart Team Developer Profile
2 plugins · 400 total installs
How We Detect immonex Kickstart Team
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/immonex-kickstart-team/dist/css/admin.css/wp-content/plugins/immonex-kickstart-team/dist/css/frontend.css/wp-content/plugins/immonex-kickstart-team/dist/js/backend.js/wp-content/plugins/immonex-kickstart-team/dist/js/frontend.jsimmonex-kickstart-team/dist/css/admin.css?ver=immonex-kickstart-team/dist/css/frontend.css?ver=immonex-kickstart-team/dist/js/backend.js?ver=immonex-kickstart-team/dist/js/frontend.js?ver=HTML / DOM Fingerprints
immonex-kickstart-team<!-- immonex Kickstart Team --><!-- immonex-kickstart-team-plugin -->data-immonex-kickstart-teamimmonexKickstartTeamimmonex_kickstart_team_i18n/wp-json/immonex-kickstart-team/[inx-team-agency