My IDX Home Search Security & Risk Analysis

wordpress.org/plugins/my-idx-home-search

Supercharge your real estate website for lead generation with a powerful IDX Home Search made by the creators of the leading MLS search for Facebook.

200 active installs v2.1.2 PHP 7.4+ WP 4.0+ Updated Dec 17, 2024
home-asapidxmlsproperty-listingsreal-estate
91
A · Safe
CVEs total2
Unpatched0
Last CVEDec 13, 2024
Safety Verdict

Is My IDX Home Search Safe to Use in 2026?

Generally Safe

Score 91/100

My IDX Home Search has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Dec 13, 2024Updated 1yr ago
Risk Assessment

The static analysis of "my-idx-home-search" v2.1.2 indicates a strong adherence to secure coding practices. The absence of any detected dangerous functions, raw SQL queries, unescaped output, file operations, or external HTTP requests is commendable. Furthermore, the complete lack of identified taint flows, especially those with critical or high severity, suggests robust input validation and sanitization within the analyzed code. The plugin also appears to have a minimal attack surface from a static perspective, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events identified without proper security checks.

Key Concerns

  • Two medium severity CVEs in vulnerability history
  • No nonce checks found in static analysis
  • No capability checks found in static analysis
Vulnerabilities
2

My IDX Home Search Security Vulnerabilities

CVEs by Year

2 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-12502medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

My IDX Home Search <= 2.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 13, 2024 Patched in 2.1.2 (8d)
CVE-2024-11889medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

My IDX Home Search <= 2.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 13, 2024 Patched in 2.1.2 (8d)
Code Analysis
Analyzed Mar 16, 2026

My IDX Home Search Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
34 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped34 total outputs
Attack Surface

My IDX Home Search Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionplugins_loadedincludes\class-homeasap-search.php:142
actionadmin_menuincludes\class-homeasap-search.php:157
actionadmin_enqueue_scriptsincludes\class-homeasap-search.php:159
actionadmin_enqueue_scriptsincludes\class-homeasap-search.php:160
actionwp_enqueue_scriptsincludes\class-homeasap-search.php:175
actionwp_enqueue_scriptsincludes\class-homeasap-search.php:176
Maintenance & Trust

My IDX Home Search Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 17, 2024
PHP min version7.4
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs200
Developer Profile

My IDX Home Search Developer Profile

Home ASAP

2 plugins · 300 total installs

94
trust score
Avg Security Score
91/100
Avg Patch Time
6 days
View full developer profile
Detection Fingerprints

How We Detect My IDX Home Search

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/my-idx-home-search/css/homeasap-search-admin.css/wp-content/plugins/my-idx-home-search/js/homeasap-search-admin.js
Script Paths
/wp-content/plugins/my-idx-home-search/js/homeasap-search-admin.js
Version Parameters
my-idx-home-search/css/homeasap-search-admin.css?ver=my-idx-home-search/js/homeasap-search-admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-plugin-name="homeasap-search"
JS Globals
homeasap_search_object
FAQ

Frequently Asked Questions about My IDX Home Search