PeakIDX Real Estate Search & Lead Generation Security & Risk Analysis

wordpress.org/plugins/peakidx-real-estate

Best In Class Website IDX - Premiere Search & Lead Generation for Real Estate Professionals

0 active installs v1.0.4 PHP 7.4+ WP 5.7+ Updated Jan 13, 2026
idxmlsproperty-searchreal-estate-listingsreal-estate
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PeakIDX Real Estate Search & Lead Generation Safe to Use in 2026?

Generally Safe

Score 100/100

PeakIDX Real Estate Search & Lead Generation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The peakidx-real-estate plugin v1.0.4 exhibits a generally good security posture, with no known vulnerabilities in its history and a low attack surface. The static analysis reveals strong adherence to secure coding practices, including the exclusive use of prepared statements for SQL queries and a high percentage of properly escaped output. The presence of nonce and capability checks further indicates an effort to implement basic security measures. However, the static analysis did identify two flows with unsanitized paths, which could potentially lead to vulnerabilities if not handled correctly within the plugin's logic. While these did not manifest as critical or high severity in the taint analysis, they represent a specific area of concern that warrants further investigation by the developer.

The absence of any recorded CVEs and a clean vulnerability history are significant strengths, suggesting the plugin has been developed with security in mind or has been relatively stable. The limited entry points, with no unprotected AJAX handlers or REST API routes, are also positive indicators. The plugin's reliance on external HTTP requests is minimal and its file operations are absent, reducing potential attack vectors. Overall, the plugin appears robust, but the identified unsanitized paths in the taint analysis are the primary weaknesses that could be exploited if they lead to exploitable functions.

Key Concerns

  • Flows with unsanitized paths identified
  • External HTTP requests present
Vulnerabilities
None known

PeakIDX Real Estate Search & Lead Generation Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

PeakIDX Real Estate Search & Lead Generation Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
36 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

86% escaped42 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
peakidx_real_estate_page_handler (peakidx-real-estate-page.php:5)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

PeakIDX Real Estate Search & Lead Generation Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[peakidx-react-component] peakidx-real-estate.php:76
WordPress Hooks 15
actiontemplate_redirectpeakidx-real-estate-proxy.php:13
filterpre_get_document_titlepeakidx-real-estate-proxy.php:14
filtertemplate_includepeakidx-real-estate-proxy.php:15
filtersafe_style_csspeakidx-real-estate-proxy.php:17
actionadmin_initpeakidx-real-estate.php:68
filterquery_varspeakidx-real-estate.php:69
actioninitpeakidx-real-estate.php:70
filterredirect_canonicalpeakidx-real-estate.php:71
actionpre_get_postspeakidx-real-estate.php:72
actionadmin_menupeakidx-real-estate.php:73
actionwp_enqueue_scriptspeakidx-real-estate.php:74
filterscript_loader_tagpeakidx-real-estate.php:75
filtertemplate_includepeakidx-real-estate.php:79
actionadmin_noticespeakidx-real-estate.php:251
filterwp_script_attributespeakidx-real-estate.php:443
Maintenance & Trust

PeakIDX Real Estate Search & Lead Generation Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJan 13, 2026
PHP min version7.4
Downloads221

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

PeakIDX Real Estate Search & Lead Generation Developer Profile

PeakIDX

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PeakIDX Real Estate Search & Lead Generation

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/peakidx-real-estate/build/index.css/wp-content/plugins/peakidx-real-estate/build/index.js/wp-content/plugins/peakidx-real-estate/css/peakidx-real-estate-styles.css/wp-content/plugins/peakidx-real-estate/js/peakidx-real-estate.js
Script Paths
/wp-content/plugins/peakidx-real-estate/build/index.js
Version Parameters
peakidx-real-estate/build/index.css?ver=peakidx-real-estate/build/index.js?ver=peakidx-real-estate/css/peakidx-real-estate-styles.css?ver=peakidx-real-estate/js/peakidx-real-estate.js?ver=

HTML / DOM Fingerprints

CSS Classes
peakidx-real-estate-container
HTML Comments
<!-- PEAKIDXPROXYSTART --><!-- PEAKIDXPROXYEND -->
Data Attributes
data-peakidx-embed-modedata-peakidx-urldata-peakidx-prefixdata-peakidx-api-keydata-peakidx-property-id
JS Globals
PeakIDX_Real_Estate_Pluginpeakidx_real_estate_dev_config_httppeakidx_real_estate_jetpress_setTagpeakidx_real_estate_data
Shortcode Output
[peakidx-react-component
FAQ

Frequently Asked Questions about PeakIDX Real Estate Search & Lead Generation