
Civic Job Posting Security & Risk Analysis
wordpress.org/plugins/civic-job-postingCivic Job Posting offers a mechanism to easily handle the medatadata of your job postings in order for them to appear in the special Job section of Go …
Is Civic Job Posting Safe to Use in 2026?
Generally Safe
Score 85/100Civic Job Posting has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The civic-job-posting plugin v1.2.0 exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events, especially without authentication checks, significantly limits the attack surface. Furthermore, the plugin utilizes prepared statements for all SQL queries, which is a critical security practice. The high percentage of properly escaped output also suggests good defensive programming against cross-site scripting vulnerabilities. The lack of recorded vulnerabilities in its history indicates a history of responsible development and maintenance.
However, several areas warrant attention. The presence of two flows with unsanitized paths in the taint analysis, even without critical or high severity, is a concern. While the analysis did not flag them as critical, such flows can sometimes be leveraged for path traversal or file inclusion vulnerabilities. The absence of nonce checks and capability checks is another significant weakness. This means that actions, if they exist and are triggered through other means, might not be properly authorized or protected against replay attacks. The bundled Guzzle library, while common, could be a point of concern if it is an outdated version or has known vulnerabilities, though this is not explicitly stated in the provided data.
In conclusion, the plugin has a solid foundation with a small attack surface and good SQL practices. The primary risks stem from potential path manipulation issues highlighted in the taint analysis and the notable absence of nonce and capability checks. The vulnerability history is positive, but the static analysis reveals areas that require further investigation and potential remediation to ensure robust security.
Key Concerns
- Unsanitized paths found in taint analysis
- Missing nonce checks
- Missing capability checks
- Bundled library (Guzzle) - potential version risk
Civic Job Posting Security Vulnerabilities
Civic Job Posting Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Civic Job Posting Attack Surface
WordPress Hooks 26
Maintenance & Trust
Civic Job Posting Maintenance & Trust
Maintenance Signals
Community Trust
Civic Job Posting Alternatives
Minimal Job Manager
minimal-job-manager
Minimal Job Manager is a minimal, lightweight and easy-to-use plugin for managing job listings and job applications on your WordPress website.
Instant Indexing for Google
fast-indexing-api
A very efficient yet simple plugin to take care of your indexing woos and helps get your content crawled by search bots instantly.
WP Job Manager
wp-job-manager
Create a careers page for your company website, or build a public job board for your community.
WP Job Openings – Job Listing, Career Page and Recruitment Plugin
wp-job-openings
WP Job Openings plugin is the most simple yet powerful plugin for setting up a job listing page for your WordPress website.
Job Postings
job-postings
WordPress plugin that make it easy to add job postings to your company’s website in a structured way.
Civic Job Posting Developer Profile
2 plugins · 2K total installs
How We Detect Civic Job Posting
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/civic-job-posting/css/civic-job-posting-admin.css/wp-content/plugins/civic-job-posting/js/civic-job-posting-admin.jscivic-job-posting-admin.css?ver=civic-job-posting-admin.js?ver=HTML / DOM Fingerprints
cjp-required-fieldscjp-optional-fieldsdata-cjp-input-type