
ReCRM Security & Risk Analysis
wordpress.org/plugins/recrmИмпорт объектов недвижимости и агентов из ReCRM
Is ReCRM Safe to Use in 2026?
Generally Safe
Score 100/100ReCRM has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "recrm" plugin v1.1.3 demonstrates some promising security practices, particularly in its limited attack surface and the absence of known historical vulnerabilities. The static analysis shows no AJAX handlers, REST API routes, or shortcodes without authentication checks, and a low overall number of entry points, which is a positive indicator. Furthermore, the lack of external HTTP requests and no recorded CVEs suggests a relatively stable and well-maintained codebase. However, several significant concerns warrant attention. The presence of the `unserialize` function, especially without clear sanitization or robust input validation, poses a substantial risk for object injection vulnerabilities if the plugin handles user-supplied data for unserialization. The low percentage of properly escaped outputs and the absence of nonce checks and capability checks on potential entry points like cron events also introduce potential cross-site scripting (XSS) and privilege escalation risks. The SQL query practice, while not entirely poor, could be improved with a higher percentage of prepared statements to mitigate SQL injection risks.
Key Concerns
- Dangerous function 'unserialize' present
- No nonce checks found
- No capability checks found
- Low percentage of properly escaped output
- Only 60% of SQL queries use prepared statements
- Cron events present without clear auth/checks
ReCRM Security Vulnerabilities
ReCRM Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
ReCRM Attack Surface
WordPress Hooks 15
Scheduled Events 1
Maintenance & Trust
ReCRM Maintenance & Trust
Maintenance Signals
Community Trust
ReCRM Alternatives
Estatik Real Estate Plugin
estatik
You will love its clean design, simple use, and colorful themes. WordPress real estate plugin Estatik is a worthy choice for single agents and portals
WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress
wpvr
Create stunning 360 virtual tours to impress visitors and get more clients using WPVR - the easiest virtual tour creator in WordPress.
Essential Real Estate
essential-real-estate
Completely plugins Real Estate. Management system which allows you to own and maintain a real estate marketplace, intro website.
Optima Express IDX
optima-express
Embed real estate property listings, market reports & MLS data on your WordPress site. Responsive design, great SEO & proven lead capture.
MLSImport – Download and synchronize real estate data from various MLS (Multiple Listing Services)
mlsimport
If you are the owner of a real estate theme and want to be integrated with MLSimport, feel free to contact us
ReCRM Developer Profile
2 plugins · 20 total installs
How We Detect ReCRM
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/recrm/css/recrm-admin.css/wp-content/plugins/recrm/js/recrm-admin.js/wp-content/plugins/recrm/js/recrm-admin.jsrecrm-admin.css?ver=recrm-admin.js?ver=