Realtivo-Resales Online for Houzez Security & Risk Analysis

wordpress.org/plugins/realtivo-resales-online-for-houzez

Connect the Houzez theme with Resales Online to import live property listings. Easy setup. No coding. Free to use.

20 active installs v1.0.3 PHP 7.4+ WP 5.0+ Updated Unknown
houzezmlsproperty-importerreal-estateresales-online
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Realtivo-Resales Online for Houzez Safe to Use in 2026?

Generally Safe

Score 100/100

Realtivo-Resales Online for Houzez has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin "realtivo-resales-online-for-houzez" v1.0.3 exhibits a generally strong security posture, with no reported vulnerabilities or critical security findings in the static analysis. The absence of known CVEs and the presence of nonce and capability checks on entry points are positive indicators. All SQL queries are prepared, and a high percentage of output is properly escaped, mitigating common risks like SQL injection and XSS.

However, there are potential areas of concern. The presence of two taint flows with unsanitized paths, while not classified as critical or high severity, warrants attention as these could represent subtle vulnerabilities if exploited in conjunction with other factors. Furthermore, the plugin performs external HTTP requests, which can introduce risks if the target servers are compromised or if the requests are not handled securely, potentially leading to SSRF or credential theft if sensitive data is transmitted. The single file operation, while not inherently risky, should be reviewed to ensure it's not writing to user-controlled paths or executing arbitrary code.

Overall, the plugin demonstrates good security practices, particularly in its handling of SQL and output escaping. The lack of historical vulnerabilities is a positive sign of ongoing maintenance. The primary areas for potential improvement lie in thoroughly auditing the two identified unsanitized taint flows and ensuring robust security around external HTTP requests and file operations. The absence of unpatched vulnerabilities and critical static analysis findings suggests a relatively low immediate risk, but vigilance is recommended for the identified potential weaknesses.

Key Concerns

  • Taint flows with unsanitized paths
  • External HTTP requests (potential risk)
  • File operations (needs review)
Vulnerabilities
None known

Realtivo-Resales Online for Houzez Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Realtivo-Resales Online for Houzez Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
15
115 escaped
Nonce Checks
7
Capability Checks
1
File Operations
1
External Requests
7
Bundled Libraries
0

Output Escaping

88% escaped130 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

3 flows2 with unsanitized paths
rtoh_handle_refresh_api_data (includes\post-types\data-post-type.php:402)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Realtivo-Resales Online for Houzez Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 5

authwp_ajax_rtoh_get_import_progressincludes\admin-page.php:20
authwp_ajax_rtoh_cancel_importincludes\admin-page.php:21
authwp_ajax_rtoh_start_importincludes\admin-page.php:22
authwp_ajax_rtoh_get_update_log_statusincludes\admin-page.php:23
authwp_ajax_rtoh_search_property_all_pagesincludes\post-types\data-post-type.php:269

Shortcodes 1

[rtoh_to_m2m_properties] includes\admin-page.php:90
WordPress Hooks 32
actionadmin_menuincludes\admin-page.php:16
actionadmin_enqueue_scriptsincludes\admin-page.php:17
actionadmin_enqueue_scriptsincludes\admin-page.php:18
actionadmin_enqueue_scriptsincludes\admin-page.php:19
actionadmin_initincludes\admin-page.php:250
actionget_template_part_template-parts/search/fields/feature-fieldincludes\admin-page.php:333
actionwp_after_template_partincludes\admin-page.php:336
filterget_terms_argsincludes\admin-page.php:346
filterget_termsincludes\admin-page.php:370
actionpre_get_termsincludes\admin-page.php:403
filterwp_get_attachment_urlincludes\asset\property-images.php:58
actionwpincludes\functions-log.php:174
actionrtoh_cleanup_logsincludes\functions-log.php:183
actioninitincludes\post-types\data-post-type.php:74
filtermanage_rtoh_api_data_posts_columnsincludes\post-types\data-post-type.php:92
actionmanage_rtoh_api_data_posts_custom_columnincludes\post-types\data-post-type.php:148
filtermanage_edit-rtoh_api_data_sortable_columnsincludes\post-types\data-post-type.php:160
actionpre_get_postsincludes\post-types\data-post-type.php:185
actionadmin_headincludes\post-types\data-post-type.php:203
actionadd_meta_boxesincludes\post-types\data-post-type.php:229
actionadd_meta_boxesincludes\post-types\data-post-type.php:378
actionadmin_post_rtoh_refresh_api_dataincludes\post-types\data-post-type.php:436
actionadmin_noticesincludes\post-types\data-post-type.php:561
actionadmin_initincludes\post-types\data-post-type.php:650
actioninitincludes\post-types\log-post-type.php:74
filtermanage_rtoh_update_log_posts_columnsincludes\post-types\log-post-type.php:93
actionmanage_rtoh_update_log_posts_custom_columnincludes\post-types\log-post-type.php:150
filtermanage_edit-rtoh_update_log_sortable_columnsincludes\post-types\log-post-type.php:163
actionpre_get_postsincludes\post-types\log-post-type.php:190
actionadmin_headincludes\post-types\log-post-type.php:208
actionrtoh_import_properties_cron_hookrealtivo-resales-online-for-houzez.php:27
actionrtoh_update_properties_cron_hookrealtivo-resales-online-for-houzez.php:53

Scheduled Events 4

rtoh_import_properties_cron_hook
rtoh_cleanup_logs
rtoh_import_properties_cron_hook
rtoh_update_properties_cron_hook
Maintenance & Trust

Realtivo-Resales Online for Houzez Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.4
Downloads317

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Realtivo-Resales Online for Houzez Developer Profile

Realtivo

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Realtivo-Resales Online for Houzez

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/realtivo-resales-online-for-houzez/assets/css/admin.css/wp-content/plugins/realtivo-resales-online-for-houzez/assets/js/admin-import.js/wp-content/plugins/realtivo-resales-online-for-houzez/assets/js/select2.min.js/wp-content/plugins/realtivo-resales-online-for-houzez/assets/js/logs.js
Script Paths
/wp-content/plugins/realtivo-resales-online-for-houzez/assets/js/admin-import.js/wp-content/plugins/realtivo-resales-online-for-houzez/assets/js/select2.min.js/wp-content/plugins/realtivo-resales-online-for-houzez/assets/js/logs.js
Version Parameters
realtivo-resales-online-for-houzez/assets/css/admin.css?ver=realtivo-resales-online-for-houzez/assets/js/admin-import.js?ver=realtivo-resales-online-for-houzez/assets/js/select2.min.js?ver=realtivo-resales-online-for-houzez/assets/js/logs.js?ver=

HTML / DOM Fingerprints

CSS Classes
rtoh-admin-css
Data Attributes
data-nonce-start-importdata-nonce-cancel-importdata-nonce-get-progress
JS Globals
rtohAdminrtohLogs
REST Endpoints
/wp-json/rtoh/v1/get-import-progress/wp-json/rtoh/v1/cancel-import/wp-json/rtoh/v1/start-import/wp-json/rtoh/v1/get-update-log-status
Shortcode Output
<pre>print_r($properties)</pre>
FAQ

Frequently Asked Questions about Realtivo-Resales Online for Houzez