
Realty Portal – Package Security & Risk Analysis
wordpress.org/plugins/realty-portal-packageStable tag: 0.3.4 License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.html The add-on manages your Membership type.
Is Realty Portal – Package Safe to Use in 2026?
Generally Safe
Score 85/100Realty Portal – Package has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "realty-portal-package" v0.3.9 presents a generally positive security posture, with no known vulnerabilities in its history and a clean bill of health from taint analysis. The static analysis reveals a well-structured codebase, with all identified AJAX handlers protected by authentication checks, and no unpermissioned REST API routes. Furthermore, the absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests are all strong indicators of good security practices. The presence of nonce checks, albeit limited in number, also contributes to a more secure foundation. The significant number of properly escaped outputs (69%) is a good sign, although there is room for improvement here.
However, the most notable weakness identified is the complete lack of capability checks. While nonce checks help prevent CSRF attacks on AJAX actions, they do not prevent authenticated users from performing actions they shouldn't have permission for. This is a significant oversight that could lead to privilege escalation vulnerabilities if not addressed. The absence of taint flows and known CVEs suggests that the plugin has likely undergone some level of security scrutiny or has not historically been a target for exploitation. Overall, the plugin has strengths in its handling of SQL and its limited attack surface, but the lack of capability checks is a critical area that requires immediate attention.
Key Concerns
- Missing capability checks on all entry points
- 186 total outputs, 31% not properly escaped
Realty Portal – Package Security Vulnerabilities
Realty Portal – Package Code Analysis
Output Escaping
Realty Portal – Package Attack Surface
AJAX Handlers 4
WordPress Hooks 29
Maintenance & Trust
Realty Portal – Package Maintenance & Trust
Maintenance Signals
Community Trust
Realty Portal – Package Alternatives
Realty Portal – Floor Plan
realty-portal-floor-plan
Stable tag: 0.3.1 License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.html An add-on to display detailed information of propert …
Realty Portal – Advanced Search
realty-portal-advanced-search
Stable tag: 0.3.3 License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.html An add-on to manage agents and their information rig …
Realty Portal – Agent Dashboard
realty-portal-agent-dashboard
Stable tag: 0.3.1 License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.html Fast, Powerful, Flexible solution for real estate ag …
Realty Portal – Agent Profile
realty-portal-agent-profile
Stable tag: 0.3.1 License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.html The add-on to help agents manage all personal inform …
Realty Portal – Nearby Places
realty-portal-nearby-places
Stable tag: 0.3.2 License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.html Quickly display places nearby the property.
Realty Portal – Package Developer Profile
13 plugins · 350 total installs
How We Detect Realty Portal – Package
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/realty-portal-package/assets/css/realty-portal-package.css/wp-content/plugins/realty-portal-package/assets/js/realty-portal-package.js/wp-content/plugins/realty-portal-package/assets/js/realty-portal-package-admin.js/wp-content/plugins/realty-portal-package/assets/js/realty-portal-package.js/wp-content/plugins/realty-portal-package/assets/js/realty-portal-package-admin.jsrealty-portal-package/assets/css/realty-portal-package.css?ver=realty-portal-package/assets/js/realty-portal-package.js?ver=realty-portal-package/assets/js/realty-portal-package-admin.js?ver=HTML / DOM Fingerprints
rp-pricing-tableADDON_PACKAGEADDON_PACKAGE_ADMIN[rp_pricing_table]