
Realty Portal – Agent Profile Security & Risk Analysis
wordpress.org/plugins/realty-portal-agent-profileStable tag: 0.3.1 License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.html The add-on to help agents manage all personal inform …
Is Realty Portal – Agent Profile Safe to Use in 2026?
Generally Safe
Score 85/100Realty Portal – Agent Profile has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'realty-portal-agent-profile' plugin v0.3.9 exhibits a generally positive security posture based on the provided static analysis. The absence of direct entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the analysis indicates no dangerous functions, file operations, or external HTTP requests, which are common vectors for exploitation. The consistent use of prepared statements for all SQL queries is a strong indicator of good security practice in database interaction.
However, a notable concern arises from the output escaping analysis, where only 22% of the outputs are properly escaped. This indicates a significant risk of Cross-Site Scripting (XSS) vulnerabilities. If user-supplied data is displayed without adequate sanitization, an attacker could inject malicious scripts. The lack of nonce checks and capability checks, coupled with zero recorded vulnerabilities, could suggest that either the plugin has not been extensively targeted or that the limited functionality does not expose critical areas. Nevertheless, the low output escaping rate remains a significant weakness that should be addressed.
In conclusion, while the plugin demonstrates good practices in areas like SQL injection prevention and attack surface minimization, the poor output escaping leaves it vulnerable to XSS attacks. The absence of documented vulnerabilities is positive, but it should not be seen as a guarantee of security given the identified weaknesses. Addressing the output escaping issues should be the priority to improve the plugin's overall security.
Key Concerns
- Low percentage of properly escaped output (22%)
- No nonce checks found
- No capability checks found
Realty Portal – Agent Profile Security Vulnerabilities
Realty Portal – Agent Profile Code Analysis
Output Escaping
Realty Portal – Agent Profile Attack Surface
WordPress Hooks 8
Maintenance & Trust
Realty Portal – Agent Profile Maintenance & Trust
Maintenance Signals
Community Trust
Realty Portal – Agent Profile Alternatives
Realty Portal – Floor Plan
realty-portal-floor-plan
Stable tag: 0.3.1 License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.html An add-on to display detailed information of propert …
Realty Portal – Advanced Search
realty-portal-advanced-search
Stable tag: 0.3.3 License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.html An add-on to manage agents and their information rig …
Realty Portal – Agent Dashboard
realty-portal-agent-dashboard
Stable tag: 0.3.1 License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.html Fast, Powerful, Flexible solution for real estate ag …
Realty Portal – Nearby Places
realty-portal-nearby-places
Stable tag: 0.3.2 License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.html Quickly display places nearby the property.
Realty Portal – Compare
realty-portal-compare
Stable tag: 0.3.2 License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.html An add-on that provides properties comparison to you …
Realty Portal – Agent Profile Developer Profile
13 plugins · 350 total installs
How We Detect Realty Portal – Agent Profile
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/realty-portal-agent-profile/assets/css/agent-profile.css/wp-content/plugins/realty-portal-agent-profile/assets/js/agent-profile.js/wp-content/plugins/realty-portal-agent-profile/assets/js/agent-profile.jsrealty-portal-agent-profile/assets/css/agent-profile.css?ver=realty-portal-agent-profile/assets/js/agent-profile.js?ver=HTML / DOM Fingerprints
agent-profile-formagent-profile-contentrp-agent-profile-wrapperAgent Profile ShortcodesRP Agent Profiledata-plugin-name="realty-portal-agent-profile"data-shortcode-tag="rp_agent_profile"RP_ShortcodesRP_Template[rp_agent_profile]