
Realtivo-Resales Online for Houzez Security & Risk Analysis
wordpress.org/plugins/realtivo-resales-online-for-houzezConnect the Houzez theme with Resales Online to import live property listings. Easy setup. No coding. Free to use.
Is Realtivo-Resales Online for Houzez Safe to Use in 2026?
Generally Safe
Score 100/100Realtivo-Resales Online for Houzez has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "realtivo-resales-online-for-houzez" v1.0.3 exhibits a generally strong security posture, with no reported vulnerabilities or critical security findings in the static analysis. The absence of known CVEs and the presence of nonce and capability checks on entry points are positive indicators. All SQL queries are prepared, and a high percentage of output is properly escaped, mitigating common risks like SQL injection and XSS.
However, there are potential areas of concern. The presence of two taint flows with unsanitized paths, while not classified as critical or high severity, warrants attention as these could represent subtle vulnerabilities if exploited in conjunction with other factors. Furthermore, the plugin performs external HTTP requests, which can introduce risks if the target servers are compromised or if the requests are not handled securely, potentially leading to SSRF or credential theft if sensitive data is transmitted. The single file operation, while not inherently risky, should be reviewed to ensure it's not writing to user-controlled paths or executing arbitrary code.
Overall, the plugin demonstrates good security practices, particularly in its handling of SQL and output escaping. The lack of historical vulnerabilities is a positive sign of ongoing maintenance. The primary areas for potential improvement lie in thoroughly auditing the two identified unsanitized taint flows and ensuring robust security around external HTTP requests and file operations. The absence of unpatched vulnerabilities and critical static analysis findings suggests a relatively low immediate risk, but vigilance is recommended for the identified potential weaknesses.
Key Concerns
- Taint flows with unsanitized paths
- External HTTP requests (potential risk)
- File operations (needs review)
Realtivo-Resales Online for Houzez Security Vulnerabilities
Realtivo-Resales Online for Houzez Code Analysis
Output Escaping
Data Flow Analysis
Realtivo-Resales Online for Houzez Attack Surface
AJAX Handlers 5
Shortcodes 1
WordPress Hooks 32
Scheduled Events 4
Maintenance & Trust
Realtivo-Resales Online for Houzez Maintenance & Trust
Maintenance Signals
Community Trust
Realtivo-Resales Online for Houzez Alternatives
Estatik Real Estate Plugin
estatik
You will love its clean design, simple use, and colorful themes. WordPress real estate plugin Estatik is a worthy choice for single agents and portals
Optima Express IDX
optima-express
Embed real estate property listings, market reports & MLS data on your WordPress site. Responsive design, great SEO & proven lead capture.
MLSImport – Download and synchronize real estate data from various MLS (Multiple Listing Services)
mlsimport
If you are the owner of a real estate theme and want to be integrated with MLSimport, feel free to contact us
Realtyna Organic IDX plugin + WPL Real Estate
real-estate-listing-realtyna-wpl
Your comprehensive solution for creating dynamic and feature-rich real estate websites on WordPress. Designed to cater to the diverse needs of real es …
Showcase IDX Real Estate Search & Lead Capture
showcase-idx
Add MLS listings to your website and capture more leads, all with one plugin! Showcase IDX is a top-performing real estate search plugin that's S …
Realtivo-Resales Online for Houzez Developer Profile
1 plugin · 20 total installs
How We Detect Realtivo-Resales Online for Houzez
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/realtivo-resales-online-for-houzez/assets/css/admin.css/wp-content/plugins/realtivo-resales-online-for-houzez/assets/js/admin-import.js/wp-content/plugins/realtivo-resales-online-for-houzez/assets/js/select2.min.js/wp-content/plugins/realtivo-resales-online-for-houzez/assets/js/logs.js/wp-content/plugins/realtivo-resales-online-for-houzez/assets/js/admin-import.js/wp-content/plugins/realtivo-resales-online-for-houzez/assets/js/select2.min.js/wp-content/plugins/realtivo-resales-online-for-houzez/assets/js/logs.jsrealtivo-resales-online-for-houzez/assets/css/admin.css?ver=realtivo-resales-online-for-houzez/assets/js/admin-import.js?ver=realtivo-resales-online-for-houzez/assets/js/select2.min.js?ver=realtivo-resales-online-for-houzez/assets/js/logs.js?ver=HTML / DOM Fingerprints
rtoh-admin-cssdata-nonce-start-importdata-nonce-cancel-importdata-nonce-get-progressrtohAdminrtohLogs/wp-json/rtoh/v1/get-import-progress/wp-json/rtoh/v1/cancel-import/wp-json/rtoh/v1/start-import/wp-json/rtoh/v1/get-update-log-status<pre>print_r($properties)</pre>