
PropertyEngine Widgets Shortcodes Security & Risk Analysis
wordpress.org/plugins/propertyengine-real-estateBringing PropertyEngine functionality into your Wordpress site widgets shortcodes. Standard compliants, easy to use and so on !
Is PropertyEngine Widgets Shortcodes Safe to Use in 2026?
Generally Safe
Score 85/100PropertyEngine Widgets Shortcodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "propertyengine-real-estate" plugin v1.2.5 demonstrates a generally good security posture with no known historical vulnerabilities or critical static analysis findings. The absence of known CVEs and the lack of dangerous functions are positive indicators. However, several areas raise concerns. The static analysis reveals that 100% of output is not properly escaped, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities. Furthermore, while no SQL queries were flagged as unsanitized, the absence of nonce and capability checks on potential entry points is a significant weakness. The taint analysis, although limited in scope (1 flow analyzed), did identify a flow with an unsanitized path, which could lead to vulnerabilities if that path is exploitable.
Despite the lack of historical CVEs, the presence of unescaped output and missing critical security checks like nonces and capability checks present a tangible risk. The plugin's attack surface appears minimal in terms of direct entry points like AJAX handlers and REST API routes, but the lack of robust validation and sanitization on outputs and potential paths is a significant oversight. The bundled libraries (TinyMCE, DataTables) are common, but their security depends on their own patch status, which isn't detailed here. In conclusion, while the plugin avoids common pitfalls like unpatched CVEs and raw SQL, the unescaped output and missing capability/nonce checks introduce significant risk that needs to be addressed.
Key Concerns
- 0% output escaping
- 0 capability checks
- 0 nonce checks
- Flow with unsanitized paths
PropertyEngine Widgets Shortcodes Security Vulnerabilities
PropertyEngine Widgets Shortcodes Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
PropertyEngine Widgets Shortcodes Attack Surface
WordPress Hooks 12
Maintenance & Trust
PropertyEngine Widgets Shortcodes Maintenance & Trust
Maintenance Signals
Community Trust
PropertyEngine Widgets Shortcodes Alternatives
Amazon Widgets Shortcodes
amazon-widgets-shortcodes
Keep your time and save your money with these Amazon widgets shortcodes. Standard compliants, easy to use and so on !
QuickAffiLink
quickaffilink
QuickAffiLink is an easy-to-use plugin that simplifies the display of Amazon affiliate products for WordPress site owners.
Affiliate Area Shortcodes by AffiliateWP
affiliatewp-affiliate-area-shortcodes
Customize your affiliate dashboard with 20+ powerful shortcodes. Show earnings, stats, referrals, and graphs anywhere on your site.
Column Shortcodes
column-shortcodes
Adds shortcodes to easily create columns in your posts or pages.
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
PropertyEngine Widgets Shortcodes Developer Profile
1 plugin · 10 total installs
How We Detect PropertyEngine Widgets Shortcodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/propertyengine-real-estate/lib/rte/PropertyEngineWidgetsShortcodeRteTinyMce.class.php/wp-content/plugins/propertyengine-real-estate/lib/PropertyEngineWidgetsShortcodeFilters.class.php/wp-content/plugins/propertyengine-real-estate/lib/tools/PropertyEngineWidgetsShortcodeContextLink.class.php/wp-content/plugins/propertyengine-real-estate/lib/tools/PropertyEngineWidgetsShortcodeProductPreview.class.php/wp-content/plugins/propertyengine-real-estate/lib/PropertyEngineWidgetsShortcodesAdmin.class.php