Free Property Valuation (Lead Generator) / Kostenlose Immobilienbewertung Security & Risk Analysis

wordpress.org/plugins/kostenlose-immobilienbewertung-lead-generator

Generate leads with free real estate valuations - for realtors and advertising agencies

700 active installs v1.9.5 PHP + WP 4.0+ Updated Nov 4, 2024
immobilienimmobilienbewertunglead-generatorlead-formularmakler-leads
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Free Property Valuation (Lead Generator) / Kostenlose Immobilienbewertung Safe to Use in 2026?

Generally Safe

Score 92/100

Free Property Valuation (Lead Generator) / Kostenlose Immobilienbewertung has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin "kostenlose-immobilienbewertung-lead-generator" v1.9.5 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities due to prepared statements, and file operations is highly commendable. Furthermore, the lack of external HTTP requests and the limited number of output operations, most of which are properly escaped, contribute to a reduced attack surface and mitigation of cross-site scripting risks. The absence of any recorded vulnerabilities in its history further suggests a history of secure development.

However, there are areas for improvement. The most significant concern is the complete lack of capability checks and nonce checks across all entry points. While the static analysis indicates no unprotected entry points in terms of AJAX or REST API routes, the absence of these fundamental WordPress security mechanisms means that even the two identified shortcodes could potentially be manipulated by unauthenticated or unauthorized users if they were to be exploited by other means. This oversight leaves the plugin vulnerable to privilege escalation or unintended execution if an attacker can find a way to trigger these shortcodes.

In conclusion, this plugin has a solid foundation with good practices in critical areas like SQL handling and output escaping. Its vulnerability-free history is a significant positive. Nevertheless, the complete omission of nonce and capability checks on its entry points is a substantial weakness that could be exploited. Addressing these missing checks should be the top priority to enhance its overall security.

Key Concerns

  • Missing capability checks on entry points
  • Missing nonce checks on entry points
  • Unescaped output (1 out of 7)
Vulnerabilities
None known

Free Property Valuation (Lead Generator) / Kostenlose Immobilienbewertung Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Free Property Valuation (Lead Generator) / Kostenlose Immobilienbewertung Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

86% escaped7 total outputs
Attack Surface

Free Property Valuation (Lead Generator) / Kostenlose Immobilienbewertung Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[real-estate-rating] kostenlose-immobilienbewertung-lead-generator.php:94
[immobilienbewertung] kostenlose-immobilienbewertung-lead-generator.php:95
WordPress Hooks 3
actionwp_enqueue_scriptskostenlose-immobilienbewertung-lead-generator.php:21
actionadmin_initkostenlose-immobilienbewertung-lead-generator.php:26
actionadmin_menukostenlose-immobilienbewertung-lead-generator.php:29
Maintenance & Trust

Free Property Valuation (Lead Generator) / Kostenlose Immobilienbewertung Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 4, 2024
PHP min version
Downloads12K

Community Trust

Rating90/100
Number of ratings2
Active installs700
Developer Profile

Free Property Valuation (Lead Generator) / Kostenlose Immobilienbewertung Developer Profile

leadmarkt

1 plugin · 700 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Free Property Valuation (Lead Generator) / Kostenlose Immobilienbewertung

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kostenlose-immobilienbewertung-lead-generator/dist/rerStyles.css/wp-content/plugins/kostenlose-immobilienbewertung-lead-generator/dist/iframeResizer.min.js
Script Paths
/wp-content/plugins/kostenlose-immobilienbewertung-lead-generator/dist/iframeResizer.min.js
Version Parameters
kostenlose-immobilienbewertung-lead-generator/dist/rerStyles.css?ver=kostenlose-immobilienbewertung-lead-generator/dist/iframeResizer.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
realEstateRatingContainerrealEstateRatingIframeleadmarkt-generator-immobilien
Data Attributes
data-iframe-height
JS Globals
iFrameResize
Shortcode Output
[real-estate-rating[immobilienbewertung
FAQ

Frequently Asked Questions about Free Property Valuation (Lead Generator) / Kostenlose Immobilienbewertung