Sync My Rex Security & Risk Analysis

wordpress.org/plugins/rex-sync

Providing tool to sync all listings, listing agents from Rex Software to WordPress

10 active installs v2.2.2 PHP 7.0+ WP 4.7+ Updated Jan 7, 2026
listingpropertyrealestaterexrexsoftware
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sync My Rex Safe to Use in 2026?

Generally Safe

Score 100/100

Sync My Rex has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The rex-sync plugin version 2.2.2 exhibits a generally strong security posture based on the provided static analysis. The absence of any recorded vulnerabilities or CVEs in its history, coupled with good coding practices like 100% prepared statement usage for SQL queries and robust nonce and capability checks, suggests a commitment to security by the developers. The plugin also demonstrates a high percentage of properly escaped output, minimizing the risk of cross-site scripting vulnerabilities.

However, there are minor areas for improvement. A small portion of outputs are not properly escaped, representing a potential, albeit low, risk. The presence of file operations without further context raises a slight concern, as does the single external HTTP request, which could be a vector if the external service is compromised or misconfigured. The plugin's attack surface, while currently protected, is composed solely of AJAX handlers, which warrants continued vigilance.

Overall, rex-sync v2.2.2 appears to be a secure plugin with a strong track record. The identified weaknesses are minor and well-mitigated by the overall secure coding practices employed. Continued monitoring for any future vulnerabilities and addressing the minor output escaping issues would further enhance its security.

Key Concerns

  • Some outputs are not properly escaped
  • File operations present
  • External HTTP request present
Vulnerabilities
None known

Sync My Rex Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Sync My Rex Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
14 prepared
Unescaped Output
3
24 escaped
Nonce Checks
3
Capability Checks
4
File Operations
8
External Requests
1
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

100% prepared14 total queries

Output Escaping

89% escaped27 total outputs
Attack Surface

Sync My Rex Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_rsc_download_listingsloader.php:50
authwp_ajax_rsc_validate_accountloader.php:51
authwp_ajax_rsc_delete_logloader.php:53
WordPress Hooks 8
actionadmin_initloader.php:42
actionadmin_enqueue_scriptsloader.php:43
actionadmin_menuloader.php:44
actioninitloader.php:45
actioninitloader.php:46
actionadd_meta_boxesloader.php:47
filterintermediate_image_sizes_advancedloader.php:983
actioninitupgrade.php:17
Maintenance & Trust

Sync My Rex Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 7, 2026
PHP min version7.0
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Sync My Rex Developer Profile

Phuc Pham

3 plugins · 120 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sync My Rex

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rex-sync/assets/css/backend.css/wp-content/plugins/rex-sync/assets/js/backend.js/wp-content/plugins/rex-sync/assets/js/frontend.js/wp-content/plugins/rex-sync/assets/css/frontend.css
Script Paths
/wp-content/plugins/rex-sync/assets/js/backend.js/wp-content/plugins/rex-sync/assets/js/frontend.js
Version Parameters
rex-sync/assets/css/backend.css?ver=rex-sync/assets/js/backend.js?ver=rex-sync/assets/js/frontend.js?ver=rex-sync/assets/css/frontend.css?ver=

HTML / DOM Fingerprints

CSS Classes
rex-sync-admin-pagerex-sync-settings-wraprex-sync-mapping-tablersc-button-sync
HTML Comments
<!-- rex-sync-admin-page --><!-- rex-sync-settings-wrap --><!-- rex-sync-mapping-table --><!-- rsc-button-sync -->+1 more
Data Attributes
data-nonce="rsc-settings-nonce"data-nonce="rsc-mapping-nonce"
JS Globals
RexSyncBackendRexSyncFrontend
REST Endpoints
/wp-json/rex-sync/v1/listings/wp-json/rex-sync/v1/agents/wp-json/rex-sync/v1/settings
Shortcode Output
[rex_sync_listings][rex_sync_agents]
FAQ

Frequently Asked Questions about Sync My Rex