WP Real Estate Security & Risk Analysis

wordpress.org/plugins/wprealestate

Specially for real estate agents and people who are willing to list their property listing on their own site.

40 active installs v5.5.2 PHP + WP 4.5+ Updated Sep 14, 2020
advanced-property-searchproperty-listingwordpress-real-estate-pluginwp-real-estate
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Real Estate Safe to Use in 2026?

Generally Safe

Score 85/100

WP Real Estate has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The wprealestate plugin v5.5.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and avoiding file operations and external HTTP requests. The absence of any recorded CVEs and bundled libraries is also a strong indicator of responsible development. However, several areas raise concerns. A significant portion of output (86%) is not properly escaped, presenting a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis revealed flows with unsanitized paths, including one of high severity, which could lead to serious security issues if these paths are exposed to user input without proper sanitization. The lack of capability checks on any entry points, coupled with a low number of nonce checks, suggests potential privilege escalation or unauthorized action vulnerabilities, especially if the identified unsanitized paths can be triggered by unauthenticated users.

Key Concerns

  • High percentage of unescaped output
  • Taint flow with high severity
  • No capability checks on entry points
  • Low number of nonce checks
Vulnerabilities
None known

WP Real Estate Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WP Real Estate Release Timeline

v5.5.2Current
v5.5.1
v5.5
v5.4
v5.3
v5.2
v5.1
v5.0
v4.9
v4.8
v4.7
v4.6
v4.5
v4.4
v4.3
v4.2
v4.1
v4.0
v3.7
v3.6
Code Analysis
Analyzed Mar 16, 2026

WP Real Estate Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
91
15 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared6 total queries

Output Escaping

14% escaped106 total outputs
Data Flows · Security
3 unsanitized

Data Flow Analysis

5 flows3 with unsanitized paths
SearchWidget2 (wprealestate.php:135)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP Real Estate Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 1

authwp_ajax_update_et_optionswprealestate.php:452

Shortcodes 3

[WP_RE_ADVANCED_SEARCH] functions.php:267
[WPRE_SEARCH] functions.php:268
[WPRE_LIST_PROPERTIES] shrtcd_property_list_filter.php:92
WordPress Hooks 18
actionadd_meta_boxesadm_pro_custom_details.php:4
actionsave_postadm_pro_custom_details.php:260
actioninitfunctions.php:41
filterrequestfunctions.php:53
filterwidget_textfunctions.php:279
actionadmin_initlibrary\property-images-metabox.php:22
actionsave_postlibrary\property-images-metabox.php:38
actionwp_enqueue_scriptswprealestate.php:40
actionwp_enqueue_scriptswprealestate.php:50
actionadmin_enqueue_scriptswprealestate.php:57
actioninitwprealestate.php:64
actioninitwprealestate.php:100
filtersingle_templatewprealestate.php:110
filterpage_templatewprealestate.php:122
actionadmin_menuwprealestate.php:196
actioninitwprealestate.php:277
actionadmin_enqueue_scriptswprealestate.php:330
filterpage_templatewprealestate.php:454
Maintenance & Trust

WP Real Estate Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedSep 14, 2020
PHP min version
Downloads36K

Community Trust

Rating80/100
Number of ratings14
Active installs40
Developer Profile

WP Real Estate Developer Profile

DraftPress Team

12 plugins · 613K total installs

69
trust score
Avg Security Score
85/100
Avg Patch Time
1011 days
View full developer profile
Detection Fingerprints

How We Detect WP Real Estate

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wprealestate/css/styles.css/wp-content/plugins/wprealestate/css/flexslider.css/wp-content/plugins/wprealestate/uploadify/uploadifive.css/wp-content/plugins/wprealestate/uploadify/jquery.uploadifive.min.js/wp-content/plugins/wprealestate/js/jquery.flexslider-min.js
Script Paths
/wp-content/plugins/wprealestate/js/jquery.flexslider-min.js/wp-content/plugins/wprealestate/uploadify/jquery.uploadifive.min.js
Version Parameters
wprealestate/css/styles.css?ver=wprealestate/css/flexslider.css?ver=wprealestate/uploadify/uploadifive.css?ver=wprealestate/uploadify/jquery.uploadifive.min.js?ver=wprealestate/js/jquery.flexslider-min.js?ver=

HTML / DOM Fingerprints

CSS Classes
et_re_property_search
Data Attributes
data-plugin-name="wprealestate"
JS Globals
et_re_currency
Shortcode Output
<form method="get"<input name="SearchProperty"<input name="page_id" type="hidden" value="<h2>Property Search</h2>
FAQ

Frequently Asked Questions about WP Real Estate