
WPCasa Security & Risk Analysis
wordpress.org/plugins/wpcasaFlexible WordPress plugin to create professional real estate websites and manage property listings with ease.
Is WPCasa Safe to Use in 2026?
Generally Safe
Score 90/100WPCasa has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin 'wpcasa' v1.4.3 presents a mixed security posture. On one hand, it demonstrates good practices with a high percentage of prepared SQL statements and properly escaped output, along with a decent number of nonce and capability checks. This suggests an awareness of common web security vulnerabilities. However, the presence of 7 flows with unsanitized paths in the taint analysis is a significant concern, even if no critical or high severity vulnerabilities were identified in this specific analysis. The historical vulnerability data, including one past critical CVE and three medium CVEs, points to a history of security weaknesses. The common vulnerability types (Code Injection, XSS, Authorization Bypass) are serious and indicate recurring issues with input validation and access control. While no currently unpatched CVEs are listed, the past severity of vulnerabilities and the taint analysis findings warrant caution.
Key Concerns
- 7 flows with unsanitized paths
- Past critical CVE history
- Past medium CVE history (3)
- Common vulnerability types (Code Inj, XSS, Auth Bypass)
WPCasa Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
WPCasa <= 1.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
WPCasa <= 1.4.1 - Unauthenticated Code Injection
WPCasa <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
WPCasa <= 1.2.13 - Insecure Direct Object Reference
WPCasa Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WPCasa Attack Surface
Shortcodes 6
WordPress Hooks 108
Scheduled Events 1
Maintenance & Trust
WPCasa Maintenance & Trust
Maintenance Signals
Community Trust
WPCasa Alternatives
Easy Property Listings
easy-property-listings
Fast. Flexible. Forward-thinking solution for real estate agents using WordPress. Built for scale, listing management and works with any theme.
Spacento – Property listings for Real estate agents
spacento
Create real estate listings website. Add property, get leads.
Essential Real Estate
essential-real-estate
Completely plugins Real Estate. Management system which allows you to own and maintain a real estate marketplace, intro website.
Diverse Solutions IDX Real Estate Listings & MLS Search
dsidxpress
Easily add mobile and SEO-friendly MLS listings to your website to attract & engage visitors, plus lead capture tools to turn them into clients.
Real Estate Manager – Property Listing and Agent Management
real-estate-manager
A comprehensive WordPress plugin designed to create feature-rich real estate websites and portals including Agent Management System.
WPCasa Developer Profile
10 plugins · 3K total installs
How We Detect WPCasa
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpcasa/assets/js/jquery.tipTip.js/wp-content/plugins/wpcasa/assets/js/jquery.cookie.js/wp-content/plugins/wpcasa/assets/css/wpcasa.css/wp-content/plugins/wpcasa/assets/js/jquery.tipTip.js/wp-content/plugins/wpcasa/assets/js/jquery.cookie.jswpcasa/assets/js/jquery.tipTip.js?ver=wpcasa/assets/js/jquery.cookie.js?ver=wpcasa/assets/css/wpcasa.css?ver=HTML / DOM Fingerprints
wpsight-property-listing<!-- BEGIN Shortcode: wpsight_listings --><!-- END Shortcode: wpsight_listings -->data-wpsight-map-latdata-wpsight-map-lngdata-wpsight-map-zoomWPSightMap/wp-json/wpcasa/v1/listings<div class="wpsight-listings">