
ApplyOnline – Application Form Builder and Manager Security & Risk Analysis
wordpress.org/plugins/apply-onlinePowerful & intuitive plugin to post ads and start receiving applications online.
Is ApplyOnline – Application Form Builder and Manager Safe to Use in 2026?
Generally Safe
Score 97/100ApplyOnline – Application Form Builder and Manager has a strong security track record. Known vulnerabilities have been patched promptly.
The 'apply-online' plugin v2.6.8.1 presents a mixed security posture. While it demonstrates some good practices, such as a relatively low number of critical and high severity vulnerabilities historically and a good percentage of SQL queries using prepared statements and properly escaped outputs, there are significant areas of concern. The presence of two AJAX handlers without authentication checks is a direct entry point for potential unauthorized actions. Furthermore, the historical vulnerability data, with six medium severity CVEs, particularly related to 'Files or Directories Accessible to External Parties', 'Missing Authorization', and 'Cross-site Scripting', indicates a recurring pattern of exploitable weaknesses. Although no critical or high vulnerabilities are currently unpatched, the history suggests a tendency for the plugin to be a target for security flaws. The use of the `unserialize` function, a known risky function, also adds to the potential attack surface, especially if user-controlled data is involved without proper sanitization. Overall, while not currently in a critical state, the plugin requires careful monitoring and proactive patching due to its past and ongoing exploitable characteristics.
Key Concerns
- AJAX handlers without auth checks
- Use of unserialize function
- 6 medium severity CVEs in history
- SQL queries not fully prepared
- Output escaping not fully utilized
ApplyOnline – Application Form Builder and Manager Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
ApplyOnline – Application Form Builder and Manager <= 2.6.7.1 - Missing Authorization
ApplyOnline <= 2.6.2 - Unauthenticated Application Disclosure
ApplyOnline – Application Form Builder and Manager <= 2.6.2 - Missing Authorization to Sensitive Information Exposure
ApplyOnline – Application Form Builder and Manager <= 2.5.2 - Missing Authorization
ApplyOnline – Application Form Builder and Manager <= 2.5.5 - Reflected Cross-Site Scripting
ApplyOnline – Application Form Builder and Manager <= 2.5.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
ApplyOnline – Application Form Builder and Manager Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
ApplyOnline – Application Form Builder and Manager Attack Surface
AJAX Handlers 7
Shortcodes 7
WordPress Hooks 63
Maintenance & Trust
ApplyOnline – Application Form Builder and Manager Maintenance & Trust
Maintenance Signals
Community Trust
ApplyOnline – Application Form Builder and Manager Alternatives
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
fluentform
Get a fast contact form plugin. Create advanced forms using drag and drop form builder with all smart features.
SureForms – Contact Form, Payment Form & Other Custom Form Builder
sureforms
The most beginner-friendly, AI Form Builder for WordPress to create contact forms, payment forms & other custom forms with advanced features, with …
Custom Form Builder, Contact Forms, Payment Forms, Surveys, Polls
powr-pack
The best 60 plugins for WP. Easy contact form plugin, social feed, popup, countdown, and more.
The Innovative Form Builder – IvyForms
ivyforms
The most innovative WordPress Form Builder plugin. Build awesome contact, order, registration, custom forms, and more in minutes.
FormGlut — Contact, Newsletter & Multi-step Form Builder
formglut
User friendly, Lightweight, Drag & Drop form builder to create your WordPress Forms
ApplyOnline – Application Form Builder and Manager Developer Profile
2 plugins · 12K total installs
How We Detect ApplyOnline – Application Form Builder and Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/apply-online/css/select2.min.css/wp-content/plugins/apply-online/css/applyonline-admin.css/wp-content/plugins/apply-online/select2/css/select2.min.css/wp-content/plugins/apply-online/css/jquery-ui.min.css/wp-content/plugins/apply-online/js/applyonline-admin.js/wp-content/plugins/apply-online/js/select2.min.js/wp-content/plugins/apply-online/js/applyonline-admin.js/wp-content/plugins/apply-online/js/select2.min.jsapply-online/css/select2.min.css?ver=apply-online/css/applyonline-admin.css?ver=apply-online/select2/css/select2.min.css?ver=apply-online/css/jquery-ui.min.css?ver=apply-online/js/applyonline-admin.js?ver=apply-online/js/select2.min.js?ver=HTML / DOM Fingerprints
aol-input-fieldaol-field-divaol-submit-buttonaol-form-wrapaol-form-builder-wrap<!-- Default value --><!-- For a select option --><!-- For a radio option --><!-- For a checkbox option -->+11 moredata-aol-field-typedata-aol-form-iddata-aol-field-iddata-aol-field-namedata-aol-field-placeholderaol_admin/wp-json/applyonline/v1/forms/wp-json/applyonline/v1/submissions/wp-json/applyonline/v1/settings<form id="apply-online-form"<div class="apply-online-form-wrapper"<input type="hidden" name="apply_online_nonce" value="