
onOffice for WP-Websites Security & Risk Analysis
wordpress.org/plugins/onoffice-for-wp-websitesIntegrate real estates, contact forms and contact persons from the onOffice Software into your WordPress website.
Is onOffice for WP-Websites Safe to Use in 2026?
Generally Safe
Score 97/100onOffice for WP-Websites has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'onoffice-for-wp-websites' plugin v6.11 presents a mixed security posture. On the positive side, it demonstrates good practices in SQL query handling, with 88% using prepared statements, and a substantial portion of output (75%) is properly escaped. The plugin also implements a reasonable number of nonce and capability checks, and it has no currently unpatched known vulnerabilities. However, there are significant concerns regarding its attack surface and the presence of unsanitized data flows.
The static analysis reveals a concerning number of unprotected AJAX handlers (4 out of 6), creating potential entry points for attackers. The taint analysis highlights 6 flows with unsanitized paths, all categorized as high severity, indicating a risk of data manipulation or injection if these flows are not properly handled before reaching sensitive operations. The vulnerability history, while not showing unpatched critical or high severity issues, does reveal a pattern of past medium severity vulnerabilities related to missing authorization and SQL injection, suggesting recurring weaknesses in these areas.
In conclusion, while the plugin has strengths in its database interaction and output handling, the significant number of unprotected AJAX endpoints and critical taint flows are substantial security risks. The historical pattern of past vulnerabilities reinforces the need for vigilance regarding authorization and SQL injection. The plugin's overall security can be improved by addressing the unprotected entry points and thoroughly sanitizing all data flows, especially those identified by the taint analysis.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized taint flows
- Past SQL injection vulnerabilities
- Past missing authorization vulnerabilities
- Use of 'assert' dangerous function
- Use of 'unserialize' dangerous function
onOffice for WP-Websites Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
onOffice for WP-Websites <= 6.5.1 - Authenticated (Editor+) SQL Injection
onOffice for WP-Websites <= 5.7 - Missing Authorization
onOffice for WP-Websites <= 6.5 - Authenticated (Administrator+) SQL Injection
onOffice for WP-Websites Release Timeline
onOffice for WP-Websites Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
onOffice for WP-Websites Attack Surface
AJAX Handlers 6
WordPress Hooks 76
Scheduled Events 3
Maintenance & Trust
onOffice for WP-Websites Maintenance & Trust
Maintenance Signals
Community Trust
onOffice for WP-Websites Alternatives
Estatik Real Estate Plugin
estatik
You will love its clean design, simple use, and colorful themes. WordPress real estate plugin Estatik is a worthy choice for single agents and portals
Optima Express IDX
optima-express
Embed real estate property listings, market reports & MLS data on your WordPress site. Responsive design, great SEO & proven lead capture.
WP VR – 360 Panorama and Virtual Tour Builder
wpvr
Create stunning 360 virtual tours to impress visitors and get more clients using WPVR - an easy virtual tour creator.
Essential Real Estate
essential-real-estate
Completely plugins Real Estate. Management system which allows you to own and maintain a real estate marketplace, intro website.
Easy Property Listings
easy-property-listings
Fast. Flexible. Forward-thinking solution for real estate agents using WordPress. Built for scale, listing management and works with any theme.
onOffice for WP-Websites Developer Profile
1 plugin · 1K total installs
How We Detect onOffice for WP-Websites
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/onoffice-for-wp-websites/build/app.css/wp-content/plugins/onoffice-for-wp-websites/build/app.js/wp-content/plugins/onoffice-for-wp-websites/build/admin.css/wp-content/plugins/onoffice-for-wp-websites/build/admin.js/wp-content/plugins/onoffice-for-wp-websites/build/vendors.css/wp-content/plugins/onoffice-for-wp-websites/build/vendors.js/wp-content/plugins/onoffice-for-wp-websites/build/vendors.css.map/wp-content/plugins/onoffice-for-wp-websites/build/vendors.js.map+15 more/wp-content/plugins/onoffice-for-wp-websites/build/app.js/wp-content/plugins/onoffice-for-wp-websites/build/admin.js/wp-content/plugins/onoffice-for-wp-websites/build/vendors.js/wp-content/plugins/onoffice-for-wp-websites/resources/js/admin.js/wp-content/plugins/onoffice-for-wp-websites/resources/js/app.js/wp-content/plugins/onoffice-for-wp-websites/resources/vendors/js/vendors.js+2 moreonoffice-for-wp-websites/build/app.css?ver=onoffice-for-wp-websites/build/app.js?ver=onoffice-for-wp-websites/build/admin.css?ver=onoffice-for-wp-websites/build/admin.js?ver=onoffice-for-wp-websites/build/vendors.css?ver=onoffice-for-wp-websites/build/vendors.js?ver=onoffice-for-wp-websites/resources/css/admin.css?ver=onoffice-for-wp-websites/resources/css/app.css?ver=onoffice-for-wp-websites/resources/js/admin.js?ver=onoffice-for-wp-websites/resources/js/app.js?ver=onoffice-for-wp-websites/resources/vendors/css/vendors.css?ver=onoffice-for-wp-websites/resources/vendors/js/vendors.js?ver=onoffice-for-wp-websites/assets/css/onoffice.css?ver=onoffice-for-wp-websites/assets/js/onoffice.js?ver=onoffice-for-wp-websites/assets/css/onoffice-style.css?ver=onoffice-for-wp-websites/assets/css/admin.css?ver=onoffice-for-wp-websites/assets/js/admin.js?ver=HTML / DOM Fingerprints
onofficeonoffice-clear-cacheaddressesestatesformssettingsonoffice_plugin_version/wp-json/onoffice/v1/plugin/wp-json/onoffice/v1/users/wp-json/onoffice/v1/addresses/wp-json/onoffice/v1/estates