PropertyEngine Widgets Shortcodes Security & Risk Analysis

wordpress.org/plugins/propertyengine-real-estate

Bringing PropertyEngine functionality into your Wordpress site widgets shortcodes. Standard compliants, easy to use and so on !

10 active installs v1.2.5 PHP + WP 2.5+ Updated Aug 7, 2013
affiliatemonetizationpropertyengineshortcodeshortcodes
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PropertyEngine Widgets Shortcodes Safe to Use in 2026?

Generally Safe

Score 85/100

PropertyEngine Widgets Shortcodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The "propertyengine-real-estate" plugin v1.2.5 demonstrates a generally good security posture with no known historical vulnerabilities or critical static analysis findings. The absence of known CVEs and the lack of dangerous functions are positive indicators. However, several areas raise concerns. The static analysis reveals that 100% of output is not properly escaped, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities. Furthermore, while no SQL queries were flagged as unsanitized, the absence of nonce and capability checks on potential entry points is a significant weakness. The taint analysis, although limited in scope (1 flow analyzed), did identify a flow with an unsanitized path, which could lead to vulnerabilities if that path is exploitable.

Despite the lack of historical CVEs, the presence of unescaped output and missing critical security checks like nonces and capability checks present a tangible risk. The plugin's attack surface appears minimal in terms of direct entry points like AJAX handlers and REST API routes, but the lack of robust validation and sanitization on outputs and potential paths is a significant oversight. The bundled libraries (TinyMCE, DataTables) are common, but their security depends on their own patch status, which isn't detailed here. In conclusion, while the plugin avoids common pitfalls like unpatched CVEs and raw SQL, the unescaped output and missing capability/nonce checks introduce significant risk that needs to be addressed.

Key Concerns

  • 0% output escaping
  • 0 capability checks
  • 0 nonce checks
  • Flow with unsanitized paths
Vulnerabilities
None known

PropertyEngine Widgets Shortcodes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

PropertyEngine Widgets Shortcodes Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
2

Bundled Libraries

TinyMCEDataTables

Output Escaping

0% escaped1 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<options> (admin\form\options.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

PropertyEngine Widgets Shortcodes Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actioninitpropertyengine-widgets-shortcodes.php:39
filterthe_excerptpropertyengine-widgets-shortcodes.php:51
filterthe_contentpropertyengine-widgets-shortcodes.php:52
filterthe_excerptpropertyengine-widgets-shortcodes.php:61
filterthe_contentpropertyengine-widgets-shortcodes.php:62
actionwp_footerpropertyengine-widgets-shortcodes.php:63
actionwp_footerpropertyengine-widgets-shortcodes.php:70
actionadmin_menupropertyengine-widgets-shortcodes.php:81
actionwpmu_new_blogpropertyengine-widgets-shortcodes.php:82
filterwhitelist_optionspropertyengine-widgets-shortcodes.php:83
actionedit_form_advancedpropertyengine-widgets-shortcodes.php:87
actionadmin_noticespropertyengine-widgets-shortcodes.php:92
Maintenance & Trust

PropertyEngine Widgets Shortcodes Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedAug 7, 2013
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

PropertyEngine Widgets Shortcodes Developer Profile

propertyengine

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PropertyEngine Widgets Shortcodes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/propertyengine-real-estate/lib/rte/PropertyEngineWidgetsShortcodeRteTinyMce.class.php/wp-content/plugins/propertyengine-real-estate/lib/PropertyEngineWidgetsShortcodeFilters.class.php/wp-content/plugins/propertyengine-real-estate/lib/tools/PropertyEngineWidgetsShortcodeContextLink.class.php/wp-content/plugins/propertyengine-real-estate/lib/tools/PropertyEngineWidgetsShortcodeProductPreview.class.php/wp-content/plugins/propertyengine-real-estate/lib/PropertyEngineWidgetsShortcodesAdmin.class.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about PropertyEngine Widgets Shortcodes