
WP Immo Manager Security & Risk Analysis
wordpress.org/plugins/wp-immo-managerWP Immo Manager integriert Immobilien aus ihrer Makler-Software in Wordpress. OpenImmo Import ihrer Immobilien aus einer Immo-Verwaltungssoftware.
Is WP Immo Manager Safe to Use in 2026?
Generally Safe
Score 92/100WP Immo Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-immo-manager plugin version 2.3.4 exhibits a mixed security posture. While it demonstrates strengths in its handling of SQL queries with a 100% prepared statement usage and a lack of recorded vulnerability history, several areas raise concerns. The presence of 50 dangerous function calls, specifically 'unserialize', without clear context on their sanitization, represents a significant potential risk. Furthermore, the static analysis reveals two AJAX handlers that lack authentication checks, creating a direct attack vector for unauthenticated users.
The low percentage of properly escaped output (17%) is another critical weakness, suggesting a high probability of cross-site scripting (XSS) vulnerabilities. The taint analysis showing zero flows is a positive indicator, but it doesn't negate the risks identified by the static analysis. The plugin's history of zero CVEs is encouraging and might indicate diligent development or recent discovery, but it should not be relied upon as a sole security guarantee.
In conclusion, while the plugin benefits from secure SQL practices and a clean vulnerability track record, the unauthenticated AJAX endpoints and widespread potential for XSS due to poor output escaping are serious concerns that require immediate attention. The usage of unserialize also presents a potential avenue for attack if not handled with extreme care.
Key Concerns
- Unauthenticated AJAX handlers
- High percentage of unescaped output
- Presence of dangerous function: unserialize
- Bundled outdated jQuery library
WP Immo Manager Security Vulnerabilities
WP Immo Manager Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
WP Immo Manager Attack Surface
AJAX Handlers 2
Shortcodes 4
WordPress Hooks 38
Scheduled Events 2
Maintenance & Trust
WP Immo Manager Maintenance & Trust
Maintenance Signals
Community Trust
WP Immo Manager Alternatives
Free Property Valuation (Lead Generator) / Kostenlose Immobilienbewertung
kostenlose-immobilienbewertung-lead-generator
Generate leads with free real estate valuations - for realtors and advertising agencies
immonex Kickstart
immonex-kickstart
Essential components and add-on framework for embedding and searching/filtering imported OpenImmo-XML-based real estate offers
immonex Kickstart Team
immonex-kickstart-team
immonex Kickstart add-on for handling, linking and embedding OpenImmo-XML-based real estate agent/agency information and contact forms
Immocaster WordPress Plugin
immocaster
Das Wordpress Plugin von Immocaster ermöglicht die Anzeige von Immobilien von ImmobilienScout24 im eingehen Blog.
Grundly – Immobilienbewertung und Wertermittlung für Makler
grundly-immobilienbewertung-wertermittlung-fuer-makler
Property valuation lead generator for real estate agents. Add the Grundly widget with shortcode and collect homeowner leads in minutes.
WP Immo Manager Developer Profile
2 plugins · 110 total installs
How We Detect WP Immo Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-immo-manager/scss/main.css/wp-content/plugins/wp-immo-manager/bootstrap-3.3.0/dist/css/bootstrap.css/wp-content/plugins/wp-immo-manager/bootstrap-3.3.0/dist/js/bootstrap.js/wp-content/plugins/wp-immo-manager/js/main.jshttps://use.fontawesome.com/a043743ff2.jsHTML / DOM Fingerprints
wpi_immobilie-countread-more-link<!-- Options registrieren --><!-- Validation Function --><!-- Admin-Notice to v3 Version -->data-wp-bindWPI_PLUGIN_URL[immobilien id=