Neptune Real Estate Security & Risk Analysis

wordpress.org/plugins/neptune-real-estate

Free real estate plugin for WordPress that lets you create, manage and list properties

50 active installs v1.0.8 PHP + WP 4.0.1+ Updated Sep 25, 2018
agentshousepropertiesreal-estaterealestate
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Neptune Real Estate Safe to Use in 2026?

Generally Safe

Score 85/100

Neptune Real Estate has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The static analysis of the "neptune-real-estate" v1.0.8 plugin indicates a generally good security posture in several key areas. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the potential attack surface. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, and bundled libraries are positive signs. The fact that all SQL queries utilize prepared statements is excellent practice. However, a significant concern arises from the extremely low percentage of properly escaped output (6%). This suggests a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data is likely being rendered directly in the browser without proper sanitization. The lack of nonce and capability checks, while not directly tied to any identified entry points in this analysis, represents a potential weakness if new entry points are introduced or if existing ones are not adequately protected by WordPress's core handling.

The vulnerability history shows no known CVEs, which is a strong positive indicator of the plugin's past security. This, combined with the zero taint analysis results, suggests that the current code, as analyzed, does not exhibit obvious critical or high-severity flaws. However, the extremely low output escaping rate is a critical blind spot that could easily lead to vulnerabilities that might not be immediately apparent through static taint analysis alone. The plugin's strengths lie in its minimal attack surface and robust SQL handling. Its primary weakness is the widespread lack of output escaping, which poses a substantial risk of XSS vulnerabilities. It is imperative that the developers address the output escaping issue to improve the plugin's overall security.

Key Concerns

  • Low output escaping rate
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Neptune Real Estate Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Neptune Real Estate Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
45
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

6% escaped48 total outputs
Attack Surface

Neptune Real Estate Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 29
actionplugins_loadedincludes\class-neptune-real-estate.php:179
actionadmin_enqueue_scriptsincludes\class-neptune-real-estate.php:194
actionadmin_enqueue_scriptsincludes\class-neptune-real-estate.php:195
actionwp_enqueue_scriptsincludes\class-neptune-real-estate.php:215
actionwp_enqueue_scriptsincludes\class-neptune-real-estate.php:216
actioninitincludes\class-neptune-real-estate.php:232
actioninitincludes\class-neptune-real-estate.php:241
actioninitincludes\class-neptune-real-estate.php:242
actionneptune_property_locationincludes\class-neptune-real-estate.php:252
filteracf/fields/google_map/apiincludes\class-neptune-real-estate.php:253
actionneptune_amenitiesincludes\class-neptune-real-estate.php:254
actionneptune_detailsincludes\class-neptune-real-estate.php:255
actionneptune_priceincludes\class-neptune-real-estate.php:256
actionneptune_real_estate_list_propertiesincludes\class-neptune-real-estate.php:257
actionneptune_real_estate_list_all_propertiesincludes\class-neptune-real-estate.php:258
actionplugin_initincludes\class-neptune-real-estate.php:259
actiontemplate_includeincludes\class-neptune-real-estate.php:282
actionadmin_noticesincludes\class-neptune-real-estate.php:296
actionadmin_noticesincludes\class-neptune-real-estate.php:297
actionneptune_real_estate_headerincludes\class-neptune-real-estate.php:298
actionneptune_real_estate_ctaincludes\class-neptune-real-estate.php:299
actionneptune_list_blogincludes\class-neptune-real-estate.php:300
filteracf/settings/show_adminincludes\config\class-neptune-real-estate-acf-config.php:6
filterpage_attributes_dropdown_pages_argstemplates\class-neptune-real-estate-page-template.php:40
filtertheme_page_templatestemplates\class-neptune-real-estate-page-template.php:48
filterwp_insert_post_datatemplates\class-neptune-real-estate-page-template.php:55
filtertemplate_includetemplates\class-neptune-real-estate-page-template.php:63
actionplugins_loadedtemplates\class-neptune-real-estate-page-template.php:154
actiontemplate_includetemplates\class-neptune-real-estate-template.php:33
Maintenance & Trust

Neptune Real Estate Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedSep 25, 2018
PHP min version
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

Neptune Real Estate Developer Profile

Denis B

2 plugins · 70 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Neptune Real Estate

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/neptune-real-estate/css/neptune-real-estate-admin.css/wp-content/plugins/neptune-real-estate/js/neptune-real-estate-admin.js/wp-content/plugins/neptune-real-estate/public/css/neptune-real-estate-public.css/wp-content/plugins/neptune-real-estate/public/js/neptune-real-estate-public.js/wp-content/plugins/neptune-real-estate/public/js/customizer.js/wp-content/plugins/neptune-real-estate/public/js/isotope.js/wp-content/plugins/neptune-real-estate/public/js/navigation.js/wp-content/plugins/neptune-real-estate/public/js/skip-link-focus-fix.js+2 more
Version Parameters
neptune-real-estate/css/neptune-real-estate-admin.css?ver=neptune-real-estate/js/neptune-real-estate-admin.js?ver=neptune-real-estate/public/css/neptune-real-estate-public.css?ver=neptune-real-estate/public/js/neptune-real-estate-public.js?ver=neptune-real-estate/public/js/customizer.js?ver=neptune-real-estate/public/js/isotope.js?ver=neptune-real-estate/public/js/navigation.js?ver=neptune-real-estate/public/js/skip-link-focus-fix.js?ver=neptune-real-estate/public/js/slick.min.js?ver=neptune-real-estate/public/js/waypoints.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
neptune-real-estate-slidernre-search-formneptune-real-estate-single-property
HTML Comments
<!-- Neptune Real Estate Plugin --><!-- NEPTUNE REAL ESTATE START: Search Form --><!-- NEPTUNE REAL ESTATE END: Search Form --><!-- NEPTUNE REAL ESTATE START: Property Listing -->+1 more
Data Attributes
data-property-iddata-search-filterdata-toggle="tooltip"
JS Globals
neptune_real_estate_params
Shortcode Output
[neptune_search_form][neptune_property_listing][neptune_single_property]
FAQ

Frequently Asked Questions about Neptune Real Estate