Listings for Buildium Security & Risk Analysis

wordpress.org/plugins/listings-for-buildium

Gets your buildium property listings and display them in an interactive way instead of using iframe and gives you styling and SEO freedom.

100 active installs v0.1.6 PHP 7.4+ WP 6.0+ Updated Dec 8, 2025
buildiumlistingsproperty-listingsrentals
99
A · Safe
CVEs total1
Unpatched0
Last CVEApr 11, 2025
Download
Safety Verdict

Is Listings for Buildium Safe to Use in 2026?

Generally Safe

Score 99/100

Listings for Buildium has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Apr 11, 2025Updated 5mo ago
Risk Assessment

The 'listings-for-buildium' plugin v0.1.6 exhibits a mixed security posture. On the positive side, static analysis reveals strong adherence to secure coding practices, with all SQL queries utilizing prepared statements and a high percentage of output being properly escaped. The plugin also incorporates nonce and capability checks, and there are no identified dangerous functions or external HTTP requests, which are excellent indicators of a secure development approach. The absence of critical or high-severity vulnerabilities in the past, and the fact that the one known medium-severity CSRF vulnerability is no longer present, suggests a responsible approach to patching and maintenance.

However, there are some areas of concern that warrant attention. The presence of two unsanitized paths identified during taint analysis, while not resulting in critical or high severity issues in this version, indicates a potential for future vulnerabilities if not addressed. Furthermore, the single shortcode represents an entry point that, while currently unprotected, is the only one. The plugin's vulnerability history, despite being clear of current issues, shows a past medium-severity CSRF, which, while resolved, highlights a type of vulnerability the plugin has been susceptible to. Overall, the plugin is in a relatively good state, but the identified taint flows and the historical pattern of CSRF vulnerabilities mean vigilance is still required.

Key Concerns

  • Taint flows with unsanitized paths found
  • Historical medium severity CSRF vulnerability
  • Shortcode entry point without explicit auth check
Vulnerabilities
1 published

Listings for Buildium Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-32606medium · 6.1Cross-Site Request Forgery (CSRF)

Listings for Buildium <= 0.1.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Apr 11, 2025 Patched in 0.1.6 (243d)
Version History

Listings for Buildium Release Timeline

v0.1.6Current
v0.1.51 CVE
v0.1.41 CVE
v0.1.31 CVE
v0.1.21 CVE
v0.1.11 CVE
v0.1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Listings for Buildium Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
3
25 escaped
Nonce Checks
2
Capability Checks
2
File Operations
3
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

89% escaped28 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
bldm_display_single_listing (inc\single-listing.php:9)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Listings for Buildium Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[bldm_listings] buildium-listings.php:37
WordPress Hooks 4
actioninitbuildium-listings.php:18
actionwp_enqueue_scriptsbuildium-listings.php:26
actionadmin_enqueue_scriptsbuildium-listings.php:27
actionadmin_menubuildium-listings.php:77
Maintenance & Trust

Listings for Buildium Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 8, 2025
PHP min version7.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Listings for Buildium Developer Profile

Deepak Khokhar

7 plugins · 5K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
236 days
View full developer profile
Detection Fingerprints

How We Detect Listings for Buildium

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/listings-for-buildium/css/style.css/wp-content/plugins/listings-for-buildium/css/gallery.css/wp-content/plugins/listings-for-buildium/js/main.js/wp-content/plugins/listings-for-buildium/css/admin.css/wp-content/plugins/listings-for-buildium/js/admin-main.js
Script Paths
/wp-content/plugins/listings-for-buildium/js/main.js/wp-content/plugins/listings-for-buildium/js/admin-main.js
Version Parameters
listings-for-buildium/css/style.css?ver=listings-for-buildium/css/gallery.css?ver=listings-for-buildium/js/main.js?ver=listings-for-buildium/css/admin.css?ver=listings-for-buildium/js/admin-main.js?ver=

HTML / DOM Fingerprints

CSS Classes
bldm-listings-wrapperbldm-listing-itembldm-listing-titlebldm-listing-addressbldm-listing-pricebldm-listing-detailsbldm-listing-imagebldm-listings-container+4 more
Data Attributes
data-bldm-iddata-bldm-url
JS Globals
bldm_plugin_urlbldm_listings_url
Shortcode Output
[bldm_listings]
FAQ

Frequently Asked Questions about Listings for Buildium