IMPress Listings Custom Search Widget Security & Risk Analysis

wordpress.org/plugins/wp-listings-custom-search-form

It is an add-on of IMPress Listings plugin which allow to create custom search widget for real estate listing management system.

60 active installs v1.5.2 PHP + WP 4.2+ Updated Mar 27, 2024
impress-listing-addonimpress-listingswp-listingwp-listing-addon
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is IMPress Listings Custom Search Widget Safe to Use in 2026?

Generally Safe

Score 85/100

IMPress Listings Custom Search Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The wp-listings-custom-search-form plugin version 1.5.2 demonstrates a generally good security posture, with several positive indicators. The absence of known vulnerabilities, critical taint flows, and dangerous functions is a strong sign of developer diligence regarding common security pitfalls. The plugin also adheres to good practices by using prepared statements for all SQL queries and performing capability checks on some code paths. However, a notable concern is the relatively low percentage of properly escaped output (42%). This indicates a potential risk for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not consistently sanitized before being displayed to users. The lack of nonce checks on its single shortcode, while not an immediate critical risk due to the absence of unprotected entry points in this specific analysis, could be a weakness if the shortcode's functionality were to involve sensitive actions in future versions or if the analysis missed certain contexts.

Overall, the plugin's security is strong due to its clean vulnerability history and secure handling of SQL. The primary area for improvement lies in ensuring all output is properly escaped to mitigate XSS risks. The vulnerability history, or lack thereof, suggests a mature and well-maintained codebase, which is a significant strength. The absence of AJAX handlers and REST API routes without authentication checks further solidifies its secure design in this regard. The presence of one shortcode as the sole entry point is manageable, but the lack of explicit nonce checks on it warrants attention to ensure no unforeseen vulnerabilities are introduced through it.

Key Concerns

  • Low output escaping percentage
  • No nonce checks on shortcode
Vulnerabilities
None known

IMPress Listings Custom Search Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

IMPress Listings Custom Search Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
5 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

42% escaped12 total outputs
Attack Surface

IMPress Listings Custom Search Widget Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wlsf_search_form] wp-listings-search-form-shortcode.php:2
WordPress Hooks 8
actionwidgets_initwp-listings-custom-search-form.php:124
actionwp_enqueue_scriptswp-listings-custom-search-form.php:125
actionadmin_noticeswp-listings-custom-search-form.php:158
actionadmin_initwp-listings-custom-search-form.php:168
actionadmin_noticeswp-listings-custom-search-form.php:171
actionplugins_loadedwp-listings-custom-search-form.php:185
filterin_widget_formwp-listings-custom-search-form.php:200
filterwidget_update_callbackwp-listings-custom-search-form.php:212
Maintenance & Trust

IMPress Listings Custom Search Widget Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedMar 27, 2024
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings2
Active installs60
Developer Profile

IMPress Listings Custom Search Widget Developer Profile

Anil Meena

3 plugins · 160 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect IMPress Listings Custom Search Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-listings-custom-search-form/css/wlcsf-style.css
Version Parameters
wp-listings-custom-search-form/css/wlcsf-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
listings-searchwp-listings-custom-searchwlcsw_inline_wrapperwlcsw_inline_propertywlcsw_inline_optionswlcsw_inline_btnProperty-Typesgeneral-link+1 more
Data Attributes
id="customsearchform"
FAQ

Frequently Asked Questions about IMPress Listings Custom Search Widget