
WP Immo Security & Risk Analysis
wordpress.org/plugins/wp-immoThis plugin allow you to manage properties in WordPress.
Is WP Immo Safe to Use in 2026?
Generally Safe
Score 85/100WP Immo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-immo" v1.1.4 plugin exhibits a mixed security posture. While it has no recorded historical vulnerabilities, indicating a potentially stable development history, the static analysis reveals significant areas of concern. The plugin has a small but concerning attack surface, with 2 AJAX handlers, both of which lack authentication checks. This immediately exposes them to unauthorized execution, a critical weakness. Furthermore, the taint analysis indicates 5 out of 6 flows have unsanitized paths, though none reached critical or high severity. This suggests a potential for input validation issues that could be exploited if they were to lead to more severe consequences. The low percentage of properly escaped output (19%) is also a worrying sign, increasing the risk of cross-site scripting (XSS) vulnerabilities, especially when combined with unsanitized input paths. While the plugin avoids dangerous functions and has no bundled libraries, the lack of robust authentication on AJAX endpoints and the prevalence of unsanitized paths present immediate risks that outweigh the absence of known CVEs.
Key Concerns
- AJAX handlers without auth checks
- Flows with unsanitized paths (5/6)
- Low percentage of properly escaped output
WP Immo Security Vulnerabilities
WP Immo Release Timeline
WP Immo Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Immo Attack Surface
AJAX Handlers 2
WordPress Hooks 26
Scheduled Events 1
Maintenance & Trust
WP Immo Maintenance & Trust
Maintenance Signals
Community Trust
WP Immo Alternatives
No alternatives data available yet.
WP Immo Developer Profile
5 plugins · 180 total installs
How We Detect WP Immo
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-immo/css/wpimmo.css/wp-content/plugins/wp-immo/genericons/genericons.css/wp-content/plugins/wp-immo/js/jquery-ui/jquery.ui.progressbar.min.js/wp-content/plugins/wp-immo/js/jquery-ui/jquery.ui.progressbar.min.1.7.2.js/wp-content/plugins/wp-immo/js/jquery-ui/redmond/jquery-ui-1.7.2.custom.css/wp-content/plugins/wp-immo/js/wpimmo-admin.js/wp-content/plugins/wp-immo/js/wpimmo-admin.jswp-immo/css/wpimmo.css?ver=wp-immo/genericons/genericons.css?ver=wp-immo/js/jquery-ui/jquery.ui.progressbar.min.js?ver=wp-immo/js/jquery-ui/jquery.ui.progressbar.min.1.7.2.js?ver=wp-immo/js/jquery-ui/redmond/jquery-ui-1.7.2.custom.css?ver=wp-immo/js/wpimmo-admin.js?ver=HTML / DOM Fingerprints
wpimmo_informationswpimmo_imageswpimmo_imageswpimmo.ajaxurlwpimmo.l10nwpimmo.fieldswpimmo.taxonomies