
ClayHR Job Board Security & Risk Analysis
wordpress.org/plugins/bizmerlinhr-jobboardThis Plugin enables you to pull jobs from ClayHR JobBoard and display them on your WordPress site. In this process, you use a shortcode [ClayHR_job_li …
Is ClayHR Job Board Safe to Use in 2026?
Generally Safe
Score 100/100ClayHR Job Board has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The bizmerlinhr-jobboard plugin v2.1 exhibits a generally positive security posture based on the provided static analysis. The absence of any recorded vulnerabilities (CVEs) and the absence of critical or high-severity findings in taint analysis are strong indicators of good development practices and a lack of known exploitable flaws. Furthermore, the plugin demonstrates good habits by exclusively using prepared statements for SQL queries and properly escaping all output, mitigating common web application vulnerabilities.
However, there are notable areas of concern that temper this otherwise positive assessment. The presence of two instances of the `unserialize` function is a significant risk. If the data being unserialized originates from an untrusted source, it can lead to object injection vulnerabilities, allowing attackers to execute arbitrary code. Compounding this is the complete lack of nonce checks and capability checks across all identified entry points (shortcodes). This means that any user, regardless of their logged-in status or permissions, could potentially trigger the functionality associated with these shortcodes, increasing the attack surface for the `unserialize` function.
In conclusion, while the plugin's vulnerability history is clean and it adheres to best practices for SQL and output handling, the identified risks related to `unserialize` and the lack of robust authorization and integrity checks on its entry points present a significant potential for exploitation. Remediation of these specific issues should be a priority to improve the plugin's overall security.
Key Concerns
- Dangerous function unserialize found
- Missing nonce checks on entry points
- Missing capability checks on entry points
ClayHR Job Board Security Vulnerabilities
ClayHR Job Board Code Analysis
Dangerous Functions Found
Output Escaping
ClayHR Job Board Attack Surface
Shortcodes 2
WordPress Hooks 3
Maintenance & Trust
ClayHR Job Board Maintenance & Trust
Maintenance Signals
Community Trust
ClayHR Job Board Alternatives
Greenhouse Job Board
greenhouse-job-board
Plugin to pull a job board from greenhouse.io via their API.
WP Job Manager
wp-job-manager
Create a careers page for your company website, or build a public job board for your community.
WP Job Openings – Job Listing, Career Page and Recruitment Plugin
wp-job-openings
WP Job Openings plugin is the most simple yet powerful plugin for setting up a job listing page for your WordPress website.
Simple Job Board
simple-job-board
job board plugin for job listings, managing applicants, applications, categories, job types, taxonomies, career page, job openings, and recruiters
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website
wp-job-portal
A smart, AI-powered job board plugin for WordPress. Build modern recruitment platforms with job listings, resume search, and intelligent matching.
ClayHR Job Board Developer Profile
1 plugin · 0 total installs
How We Detect ClayHR Job Board
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bizmerlinhr-jobboard/positionsPlugins.cssHTML / DOM Fingerprints
search_dialogjob-sectionjob-listingsjob-listingposting-titledata-clayhr-id[BizMerlin_job_listings][ClayHR_job_listings]