
RentPress for Websites Security & Risk Analysis
wordpress.org/plugins/rentpress-for-websitesConnects property information to any WordPress site to help market your apartments. Supports data feeds from: RentCafe, Entrata, RealPage, and more.
Is RentPress for Websites Safe to Use in 2026?
Generally Safe
Score 100/100RentPress for Websites has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "rentpress-for-websites" v7.15.7 plugin exhibits a mixed security posture. While the absence of known CVEs and a low percentage of SQL queries lacking prepared statements are positive indicators, significant concerns arise from its attack surface. A substantial number of AJAX handlers and REST API routes lack proper authentication and permission checks, presenting clear entry points for unauthorized access and manipulation.
The static analysis reveals 10 unprotected entry points out of a total of 19, including 9 AJAX handlers and 1 REST API route without adequate security measures. While the taint analysis shows no critical or high-severity vulnerabilities, this is often due to the limited scope of taint analysis, which may not fully capture the impact of unprotected entry points. The plugin's reliance on capability checks and nonce checks is also limited, further contributing to potential security weaknesses.
Overall, the plugin demonstrates good practices in output escaping and avoids bundling external libraries, which are strengths. However, the high number of unprotected AJAX and REST API endpoints is a critical flaw. The lack of any recorded past vulnerabilities could indicate either a historically secure plugin or a lack of thorough past security audits. Given the current findings, proactive patching and securing of all entry points is strongly recommended.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API route
- High number of SQL queries without prepared statements
- Limited nonce checks
- Limited capability checks
RentPress for Websites Security Vulnerabilities
RentPress for Websites Code Analysis
SQL Query Safety
Output Escaping
RentPress for Websites Attack Surface
AJAX Handlers 9
REST API Routes 1
Shortcodes 9
WordPress Hooks 80
Scheduled Events 10
Maintenance & Trust
RentPress for Websites Maintenance & Trust
Maintenance Signals
Community Trust
RentPress for Websites Alternatives
RentPress: Amenities Manager Add-on
rentpress-amenities-manager-add-on
Take control of your amenities synced from a property management software.
RentPress: Gravity Forms Add-on
rentpress-gravity-forms-add-on
RentPress: Gravity Forms Add-on connects your contact forms with your multifamily CRMs.
Domilocus
domilocus
Complete booking and property management solution for vacation rentals, apartments, and accommodations with backend administration.
Simple rental system
single-page-booking-system
This WordPress plugin integrates the simple rental booking system from i-rent.net into a selected page on the user’s website.
Discount Rules for WooCommerce
woo-discount-rules
The discount plugin for WooCommerce helps you create bulk discount, quantity discount, storewide sale, dynamic pricing discount offers easily.
RentPress for Websites Developer Profile
3 plugins · 140 total installs
How We Detect RentPress for Websites
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rentpress-for-websites/public/vue/main-app/dist/app.js/wp-content/plugins/rentpress-for-websites/public/vue/main-app/dist/app.css/wp-content/plugins/rentpress-for-websites/public/vue/mapbox-app/dist/app.js/wp-content/plugins/rentpress-for-websites/public/vue/mapbox-app/dist/app.css/wp-content/plugins/rentpress-for-websites/admin/assets/javascript/rentpress-blocks-floorplan-search-editor-script.js/wp-content/plugins/rentpress-for-websites/public/vue/main-app/dist/app.js/wp-content/plugins/rentpress-for-websites/public/vue/mapbox-app/dist/app.js/wp-content/plugins/rentpress-for-websites/admin/assets/javascript/rentpress-blocks-floorplan-search-editor-script.jsHTML / DOM Fingerprints
rentpress-single-floorplan-containerrentpress-property-search-containerdata-rentpress-image-assets-dirdata-rentpress-plugin-dir-pathdata-rentpress-plugin-dir-urlrentpressData/wp-json/rentpress/v1/remotesync[rentpress_single_floorplan][rentpress_property_search][rentpress_floorplan_search]