
Realty by BestWebSoft Security & Risk Analysis
wordpress.org/plugins/realtyCreate your personal real estate WordPress website. Sell, rent and buy properties. Add, search and browse listings easily.
Is Realty by BestWebSoft Safe to Use in 2026?
Generally Safe
Score 99/100Realty by BestWebSoft has a strong security track record. Known vulnerabilities have been patched promptly.
The "realty" plugin v1.1.6 exhibits a mixed security posture. While it boasts a low number of unprotected entry points and a good percentage of properly escaped outputs, significant concerns exist regarding its use of dangerous functions and the presence of outdated bundled libraries. The static analysis reveals the use of `unserialize`, which is inherently risky if not handled with extreme caution and proper sanitization of the serialized data source. Although taint analysis did not flag any immediate unsanitized flows, the potential for serialization vulnerabilities remains a considerable risk. The vulnerability history, while currently showing no unpatched CVEs, indicates a past pattern of medium severity vulnerabilities, specifically Cross-site Scripting (XSS). This suggests a tendency for certain types of input validation or output sanitization issues to arise within this plugin.
Overall, the plugin has strengths in its limited attack surface and output escaping. However, the reliance on `unserialize` and the inclusion of an older version of Select2 present tangible risks. The historical vulnerability pattern warrants vigilance. A balanced conclusion is that while the plugin is not critically vulnerable based on the provided data, proactive measures to secure the `unserialize` function and update bundled libraries are strongly recommended to mitigate potential threats and prevent future recurrences of past vulnerability types.
Key Concerns
- Use of dangerous function 'unserialize'
- Bundled outdated library: Select2 v3.3.2
- SQL queries: only 81% use prepared statements
Realty by BestWebSoft Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Realty by BestWebSoft <= 1.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Realty by BestWebSoft < 1.1.0 - Reflected Cross-Site Scripting
Realty by BestWebSoft Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Realty by BestWebSoft Attack Surface
AJAX Handlers 2
WordPress Hooks 40
Maintenance & Trust
Realty by BestWebSoft Maintenance & Trust
Maintenance Signals
Community Trust
Realty by BestWebSoft Alternatives
ActiveCampaign – The autonomous marketing platform
activecampaign-subscription-forms
Add ActiveCampaign contact forms and live chat to any post, page, or sidebar. Also enable ActiveCampaign site tracking for your WordPress blog.
Essential Real Estate
essential-real-estate
Completely plugins Real Estate. Management system which allows you to own and maintain a real estate marketplace, intro website.
Property Hive
propertyhive
Building a property website? Property Hive has everything you need to get started, and so much more.
IP Ban
simple-ip-ban
Simple IP Ban is a lightweight ip / user agent ban plugin.
Agent Image News
agent-image-news
Get the latest real estate Internet marketing news, website advice and tech tips from Agent Image.
Realty by BestWebSoft Developer Profile
32 plugins · 17K total installs
How We Detect Realty by BestWebSoft
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/realty/assets/css/realty-frontend.css/wp-content/plugins/realty/assets/css/responsive.css/wp-content/plugins/realty/assets/js/realty-frontend.js/wp-content/plugins/realty/assets/js/realty-admin.js/wp-content/plugins/realty/bws_menu/css/bws_menu.css/wp-content/plugins/realty/assets/js/realty-frontend.js/wp-content/plugins/realty/assets/js/realty-admin.jsrealty/assets/css/realty-frontend.css?ver=realty/assets/css/responsive.css?ver=realty/assets/js/realty-frontend.js?ver=realty/assets/js/realty-admin.js?ver=realty/bws_menu/css/bws_menu.css?ver=HTML / DOM Fingerprints
rlt_property_search_wraprealty_property_single_innerrealty-property-listingrlt-agent-single-wrap© Copyright 2020 BestWebSoft ( https://support.bestwebsoft.com )This program is free software; you can redistribute it and/or modifyThis program is distributed in the hope that it will be useful,You should have received a copy of the GNU General Public License+7 moredata-rlt-search-results-mapdata-rlt-property-mapdata-rlt-property-iddata-rlt-agent-idrealty_frontend_params/wp-json/realty/v1/properties/wp-json/realty/v1/agents[realty_property_search][realty_property_listing][realty_agent_listing]