Auto Location for WP Job Manager Security & Risk Analysis

wordpress.org/plugins/auto-location-for-wp-job-manager

Auto Location Google For WP Job Manager allow to add location autocomplete by location search.

100 active installs v1.1 PHP + WP + Updated Nov 20, 2025
google-locationgoogle-wp-job-managerwp-job-manager-locationwp-job-manager
100
A · Safe
CVEs total1
Unpatched0
Last CVEJul 3, 2023
Download
Safety Verdict

Is Auto Location for WP Job Manager Safe to Use in 2026?

Generally Safe

Score 100/100

Auto Location for WP Job Manager has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jul 3, 2023Updated 4mo ago
Risk Assessment

The static analysis of 'auto-location-for-wp-job-manager' v1.1 reveals a generally positive security posture in terms of its direct code implementations. The absence of identified dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. Furthermore, the plugin appears to handle SQL queries using prepared statements exclusively, which is a strong defense against SQL injection. The output escaping is mostly effective, with only a small percentage of outputs potentially lacking proper sanitization.

However, the static analysis also highlights significant areas of concern. The complete lack of identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) is unusual and might indicate a misunderstanding of the plugin's functionality or a very limited scope. Crucially, there are zero identified capability checks or nonce checks, which is a major red flag. This suggests that even if there were entry points, they might not be properly secured against unauthorized access or CSRF attacks.

The vulnerability history shows one past medium-severity vulnerability related to Cross-site Scripting (XSS). While this vulnerability is marked as patched, its existence and type indicate a potential weakness in input sanitization for web page generation. The lack of critical or high vulnerabilities in the history is a positive sign, but the medium XSS vulnerability and the concerning findings from the static analysis (specifically the lack of checks on entry points) suggest that the plugin is not entirely without risk and requires careful oversight.

Key Concerns

  • No capability checks found
  • No nonce checks found
  • Potential unescaped output found
  • Past medium XSS vulnerability
Vulnerabilities
1

Auto Location for WP Job Manager Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-3344medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Auto Location for WP Job Manager via Google <= 1.0 - Authenticated (Administrator+) Stored Cross Site Scripting

Jul 3, 2023 Patched in 1.1 (204d)
Code Analysis
Analyzed Mar 16, 2026

Auto Location for WP Job Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

86% escaped7 total outputs
Attack Surface

Auto Location for WP Job Manager Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_initincludes\ALGWJM_Admin.php:11
actionadmin_menuincludes\ALGWJM_Admin.php:12
actionwp_enqueue_scriptsincludes\ALGWJM_Frontend.php:12
actionwp_footerincludes\ALGWJM_Frontend.php:13
Maintenance & Trust

Auto Location for WP Job Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 20, 2025
PHP min version
Downloads4K

Community Trust

Rating60/100
Number of ratings2
Active installs100
Developer Profile

Auto Location for WP Job Manager Developer Profile

theme funda

26 plugins · 12K total installs

87
trust score
Avg Security Score
98/100
Avg Patch Time
85 days
View full developer profile
Detection Fingerprints

How We Detect Auto Location for WP Job Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/auto-location-for-wp-job-manager/assets/js/algwjm_frontend.js
Script Paths
https://maps.googleapis.com/maps/api/js

HTML / DOM Fingerprints

Data Attributes
id="search_location"id="job_location"
JS Globals
googleinitialize_gpa
FAQ

Frequently Asked Questions about Auto Location for WP Job Manager