
Free Property Valuation (Lead Generator) / Kostenlose Immobilienbewertung Security & Risk Analysis
wordpress.org/plugins/kostenlose-immobilienbewertung-lead-generatorGenerate leads with free real estate valuations - for realtors and advertising agencies
Is Free Property Valuation (Lead Generator) / Kostenlose Immobilienbewertung Safe to Use in 2026?
Generally Safe
Score 92/100Free Property Valuation (Lead Generator) / Kostenlose Immobilienbewertung has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "kostenlose-immobilienbewertung-lead-generator" v1.9.5 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities due to prepared statements, and file operations is highly commendable. Furthermore, the lack of external HTTP requests and the limited number of output operations, most of which are properly escaped, contribute to a reduced attack surface and mitigation of cross-site scripting risks. The absence of any recorded vulnerabilities in its history further suggests a history of secure development.
However, there are areas for improvement. The most significant concern is the complete lack of capability checks and nonce checks across all entry points. While the static analysis indicates no unprotected entry points in terms of AJAX or REST API routes, the absence of these fundamental WordPress security mechanisms means that even the two identified shortcodes could potentially be manipulated by unauthenticated or unauthorized users if they were to be exploited by other means. This oversight leaves the plugin vulnerable to privilege escalation or unintended execution if an attacker can find a way to trigger these shortcodes.
In conclusion, this plugin has a solid foundation with good practices in critical areas like SQL handling and output escaping. Its vulnerability-free history is a significant positive. Nevertheless, the complete omission of nonce and capability checks on its entry points is a substantial weakness that could be exploited. Addressing these missing checks should be the top priority to enhance its overall security.
Key Concerns
- Missing capability checks on entry points
- Missing nonce checks on entry points
- Unescaped output (1 out of 7)
Free Property Valuation (Lead Generator) / Kostenlose Immobilienbewertung Security Vulnerabilities
Free Property Valuation (Lead Generator) / Kostenlose Immobilienbewertung Code Analysis
Output Escaping
Free Property Valuation (Lead Generator) / Kostenlose Immobilienbewertung Attack Surface
Shortcodes 2
WordPress Hooks 3
Maintenance & Trust
Free Property Valuation (Lead Generator) / Kostenlose Immobilienbewertung Maintenance & Trust
Maintenance Signals
Community Trust
Free Property Valuation (Lead Generator) / Kostenlose Immobilienbewertung Alternatives
Grundly – Immobilienbewertung und Wertermittlung für Makler
grundly-immobilienbewertung-wertermittlung-fuer-makler
Property valuation lead generator for real estate agents. Add the Grundly widget with shortcode and collect homeowner leads in minutes.
immonex Kickstart
immonex-kickstart
Essential components and add-on framework for embedding and searching/filtering imported OpenImmo-XML-based real estate offers
immonex Kickstart Team
immonex-kickstart-team
immonex Kickstart add-on for handling, linking and embedding OpenImmo-XML-based real estate agent/agency information and contact forms
WP Immo Manager
wp-immo-manager
WP Immo Manager integriert Immobilien aus ihrer Makler-Software in Wordpress. OpenImmo Import ihrer Immobilien aus einer Immo-Verwaltungssoftware.
Immocaster WordPress Plugin
immocaster
Das Wordpress Plugin von Immocaster ermöglicht die Anzeige von Immobilien von ImmobilienScout24 im eingehen Blog.
Free Property Valuation (Lead Generator) / Kostenlose Immobilienbewertung Developer Profile
1 plugin · 700 total installs
How We Detect Free Property Valuation (Lead Generator) / Kostenlose Immobilienbewertung
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kostenlose-immobilienbewertung-lead-generator/dist/rerStyles.css/wp-content/plugins/kostenlose-immobilienbewertung-lead-generator/dist/iframeResizer.min.js/wp-content/plugins/kostenlose-immobilienbewertung-lead-generator/dist/iframeResizer.min.jskostenlose-immobilienbewertung-lead-generator/dist/rerStyles.css?ver=kostenlose-immobilienbewertung-lead-generator/dist/iframeResizer.min.js?ver=HTML / DOM Fingerprints
realEstateRatingContainerrealEstateRatingIframeleadmarkt-generator-immobiliendata-iframe-heightiFrameResize[real-estate-rating[immobilienbewertung