
Greenhouse Job Board Security & Risk Analysis
wordpress.org/plugins/greenhouse-job-boardPlugin to pull a job board from greenhouse.io via their API.
Is Greenhouse Job Board Safe to Use in 2026?
Use With Caution
Score 63/100Greenhouse Job Board has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "greenhouse-job-board" plugin v2.7.3 exhibits a mixed security posture. While it demonstrates good practices in SQL query handling with 100% prepared statements and has no reported dangerous functions or file operations, several concerning aspects emerge from the static analysis and vulnerability history. The complete lack of output escaping for all identified outputs is a significant vulnerability, exposing users to potential Cross-Site Scripting (XSS) attacks. Furthermore, the presence of external HTTP requests without clear indication of their security implications warrants caution.
The vulnerability history is particularly concerning, with one unpatched medium severity CVE related to XSS, which aligns with the output escaping issues identified in the static analysis. The fact that this vulnerability is dated in the future (2025) might indicate a placeholder or an error in the provided data, but it still signifies a known past exploit. The limited attack surface (one shortcode) is a positive, but its lack of protection, including absence of nonce and capability checks, means that the single entry point could be exploited.
In conclusion, despite some positive security practices, the "greenhouse-job-board" plugin has critical weaknesses, primarily concerning unescaped output and an unpatched XSS vulnerability. The lack of robust input validation and authorization checks on its limited attack surface amplifies these risks. Organizations using this plugin should prioritize addressing the XSS and output escaping issues.
Key Concerns
- Unpatched medium severity CVE
- 100% of outputs are unescaped
- Flow with unsanitized path found
- No nonce checks on entry points
- No capability checks on entry points
Greenhouse Job Board Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Greenhouse Job Board <= 2.7.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
Greenhouse Job Board Code Analysis
Output Escaping
Data Flow Analysis
Greenhouse Job Board Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Greenhouse Job Board Maintenance & Trust
Maintenance Signals
Community Trust
Greenhouse Job Board Alternatives
ClayHR Job Board
bizmerlinhr-jobboard
This Plugin enables you to pull jobs from ClayHR JobBoard and display them on your WordPress site. In this process, you use a shortcode [ClayHR_job_li …
WP Job Manager
wp-job-manager
Create a careers page for your company website, or build a public job board for your community.
WP Job Openings – Job Listing, Career Page and Recruitment Plugin
wp-job-openings
WP Job Openings plugin is the most simple yet powerful plugin for setting up a job listing page for your WordPress website.
Simple Job Board
simple-job-board
job board plugin for job listings, managing applicants, applications, categories, job types, taxonomies, career page, job openings, and recruiters
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website
wp-job-portal
A smart, AI-powered job board plugin for WordPress. Build modern recruitment platforms with job listings, resume search, and intelligent matching.
Greenhouse Job Board Developer Profile
1 plugin · 200 total installs
How We Detect Greenhouse Job Board
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/greenhouse-job-board/css/greenhouse-job-board-admin.css/wp-content/plugins/greenhouse-job-board/js/greenhouse-job-board-admin.js/wp-content/plugins/greenhouse-job-board/js/greenhouse-job-board-admin.jsgreenhouse-job-board/css/greenhouse-job-board-admin.css?ver=greenhouse-job-board/js/greenhouse-job-board-admin.js?ver=HTML / DOM Fingerprints
greenhouse-wizardmedia-framemedia-frame-titlemedia-frame-contentgreenhouse-job-boardid="add-greenhouse-shortcode-button"id="add-greenhouse-shortcode-form"id="url_token"id="api_key"id="apply_now"id="apply_now_cancel"+4 more[greenhouse-job-board][greenhouse-job-board url_token=""[greenhouse-job-board api_key=""[greenhouse-job-board apply_now=""