Real Estate Agency Security & Risk Analysis

wordpress.org/plugins/real-estate-agency

Transforme votre WP en site Internet pour agence immobiliere. Responsive pour mobile. This plugin relying on a 3rd party as a service to manage back o …

10 active installs v1.0.0 PHP 5.6+ WP 4.7+ Updated Jun 14, 2019
immobilierreal-estate-agencyvente-appartementvente-maison
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Real Estate Agency Safe to Use in 2026?

Generally Safe

Score 85/100

Real Estate Agency has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The plugin 'real-estate-agency' v1.0.0 exhibits a concerning security posture primarily due to a significant lack of authentication and authorization checks on its exposed entry points. With 6 AJAX handlers identified, all of which are unprotected, any user, including unauthenticated ones, can potentially trigger these functions. This wide attack surface without any access controls is a major security risk. Furthermore, while the plugin doesn't appear to use dangerous functions directly or have known historical vulnerabilities, the taint analysis reveals one flow with unsanitized paths, which could lead to unexpected behavior or vulnerabilities if it involves sensitive operations. The presence of 27 SQL queries with only 15% using prepared statements is also a red flag, indicating a high risk of SQL injection vulnerabilities. The overall lack of nonce and capability checks on AJAX handlers exacerbates these issues, making it easier for attackers to exploit potential weaknesses. While the plugin has no known CVEs, this is not a guarantee of security, especially given the identified code weaknesses. The developer should prioritize implementing proper authentication and authorization for all AJAX actions, ensure all SQL queries are prepared, and sanitize all inputs to prevent potential exploits.

Key Concerns

  • AJAX handlers without auth checks
  • Nonce checks missing on AJAX
  • Capability checks missing on AJAX
  • SQL queries with low prepared statement usage
  • Flows with unsanitized paths (taint analysis)
  • Output escaping below ideal threshold
Vulnerabilities
None known

Real Estate Agency Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Real Estate Agency Release Timeline

v1.0
Code Analysis
Analyzed Mar 17, 2026

Real Estate Agency Code Analysis

Dangerous Functions
0
Raw SQL Queries
23
4 prepared
Unescaped Output
771
1230 escaped
Nonce Checks
0
Capability Checks
0
File Operations
57
External Requests
0
Bundled Libraries
0

SQL Query Safety

15% prepared27 total queries

Output Escaping

61% escaped2001 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<vente> (theme-realestate\realestate-template-parts\root\vente.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
6 unprotected

Real Estate Agency Attack Surface

Entry Points6
Unprotected6

AJAX Handlers 6

authwp_ajax_update_pwd_wprealestateagency.php:916
authwp_ajax_logout_wp_dbrealestateagency.php:917
authwp_ajax_login_wp_dbrealestateagency.php:918
authwp_ajax_update_pwd_wp_dbrealestateagency.php:919
authwp_ajax_update_smtp_wp_dbrealestateagency.php:920
authwp_ajax_send_messagerealestateagency.php:921
WordPress Hooks 22
actioninitrealestateagency.php:24
actioninitrealestateagency.php:149
actionadmin_menurealestateagency.php:467
actiondeactivated_pluginrealestateagency.php:524
filterthe_titlerealestateagency.php:527
actionafter_setup_themerealestateagency.php:533
actioninitrealestateagency.php:636
actioninitrealestateagency.php:654
actioninitrealestateagency.php:670
actioninitrealestateagency.php:683
actioninitrealestateagency.php:700
actioninitrealestateagency.php:710
actioninitrealestateagency.php:719
actioninitrealestateagency.php:729
actioninitrealestateagency.php:739
actioninitrealestateagency.php:749
actioninitrealestateagency.php:761
actioninitrealestateagency.php:769
actionadmin_initrealestateagency.php:781
filterfrontpage_templaterealestateagency.php:801
actionphpmailer_initrealestateagency.php:809
actionadmin_enqueue_scriptsrealestateagency.php:915
Maintenance & Trust

Real Estate Agency Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.0
Last updatedJun 14, 2019
PHP min version5.6
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Real Estate Agency Developer Profile

patrickgilbert

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Real Estate Agency

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/real-estate-agency/css/style.css/wp-content/plugins/real-estate-agency/js/script.js
Script Paths
/wp-content/plugins/real-estate-agency/js/script.js
Version Parameters
real-estate-agency/style.css?ver=real-estate-agency/js/script.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Site Client Parameter --><!-- Settings --><!-- Login --><!-- Password -->+23 more
Data Attributes
id="realestate_settings"id="realestate_login"id="realestate_password"id="realestate_smtp_settings"id="realestate_smtp_user"id="realestate_smtp_pass"+26 more
JS Globals
var bodybackgroundcolorvar pcolorvar h1colorvar linkcolorvar linkhovercolorvar pricecolor+16 more
FAQ

Frequently Asked Questions about Real Estate Agency