
Auto Location for WP Job Manager Security & Risk Analysis
wordpress.org/plugins/auto-location-for-wp-job-managerAuto Location Google For WP Job Manager allow to add location autocomplete by location search.
Is Auto Location for WP Job Manager Safe to Use in 2026?
Generally Safe
Score 100/100Auto Location for WP Job Manager has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of 'auto-location-for-wp-job-manager' v1.1 reveals a generally positive security posture in terms of its direct code implementations. The absence of identified dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. Furthermore, the plugin appears to handle SQL queries using prepared statements exclusively, which is a strong defense against SQL injection. The output escaping is mostly effective, with only a small percentage of outputs potentially lacking proper sanitization.
However, the static analysis also highlights significant areas of concern. The complete lack of identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) is unusual and might indicate a misunderstanding of the plugin's functionality or a very limited scope. Crucially, there are zero identified capability checks or nonce checks, which is a major red flag. This suggests that even if there were entry points, they might not be properly secured against unauthorized access or CSRF attacks.
The vulnerability history shows one past medium-severity vulnerability related to Cross-site Scripting (XSS). While this vulnerability is marked as patched, its existence and type indicate a potential weakness in input sanitization for web page generation. The lack of critical or high vulnerabilities in the history is a positive sign, but the medium XSS vulnerability and the concerning findings from the static analysis (specifically the lack of checks on entry points) suggest that the plugin is not entirely without risk and requires careful oversight.
Key Concerns
- No capability checks found
- No nonce checks found
- Potential unescaped output found
- Past medium XSS vulnerability
Auto Location for WP Job Manager Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Auto Location for WP Job Manager via Google <= 1.0 - Authenticated (Administrator+) Stored Cross Site Scripting
Auto Location for WP Job Manager Code Analysis
Output Escaping
Auto Location for WP Job Manager Attack Surface
WordPress Hooks 4
Maintenance & Trust
Auto Location for WP Job Manager Maintenance & Trust
Maintenance Signals
Community Trust
Auto Location for WP Job Manager Alternatives
Contact Listing for WP Job Manager
wp-job-manager-contact-listing
Allow sites using the WP Job Manager plugin to contact listings via their favorite form builder plugin.
Job Manager & Career – Manage job board listings, and recruitments
job-manager-career
An ideal WordPress Job Manager plugin for recruiters to manage job board listings, career pages, and recruitments.
WP All Import – Job Listing Import for WP Job Manager
wp-job-manager-xml-csv-listings-import
Drag & drop to import job listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports company info, locations, applic …
Custom Field For WP Job Manager
custom-field-for-wp-job-manager
The ultimate field editor for WP Job Manager. Easily add, edit, and manage custom job and company fields without any coding.
Go Fetch Jobs (for WP Job Manager)
go-fetch-jobs-wp-job-manager
Instantly populate your WP Job Manager database using RSS job feeds from the most popular job sites or load XML/JSON files (premium only).
Auto Location for WP Job Manager Developer Profile
26 plugins · 12K total installs
How We Detect Auto Location for WP Job Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/auto-location-for-wp-job-manager/assets/js/algwjm_frontend.jshttps://maps.googleapis.com/maps/api/jsHTML / DOM Fingerprints
id="search_location"id="job_location"googleinitialize_gpa