
Employee, Leave and Recruitment Management System – Crew HRM Security & Risk Analysis
wordpress.org/plugins/hr-managementCreate career pages for job listings, hiring or recruiting great talent with Crew HRM. It helps manage employee info, leave requests, onboarding
Is Employee, Leave and Recruitment Management System – Crew HRM Safe to Use in 2026?
Generally Safe
Score 98/100Employee, Leave and Recruitment Management System – Crew HRM has a strong security track record. Known vulnerabilities have been patched promptly.
The "hr-management" plugin v1.2.2 exhibits a generally positive security posture with a low attack surface, primarily due to proper implementation of prepared statements for SQL queries and good output escaping practices. The absence of AJAX handlers and REST API routes without proper checks is also a strength. However, the presence of the `unserialize` function is a significant concern as it can lead to Remote Code Execution if used with untrusted input. While taint analysis shows no unsanitized flows in this specific scan, this function's inherent risk cannot be ignored.
The plugin's vulnerability history reveals a past high-severity vulnerability, specifically related to Deserialization of Untrusted Data. Although this vulnerability is reported as patched, the pattern indicates that this class of vulnerability is a recurring concern for this plugin. The fact that there is a past unpatched vulnerability of high severity, even if now patched, suggests a need for continuous vigilance and thorough code review, particularly around data handling that involves deserialization.
In conclusion, while the plugin demonstrates good security practices in many areas, the use of `unserialize` combined with its past deserialization vulnerability history presents a notable risk that warrants attention. The plugin's strengths lie in its limited attack surface and diligent use of prepared statements and output escaping. Its weaknesses center on the potential for deserialization vulnerabilities.
Key Concerns
- Use of unserialize function
- Past high severity CVE (Deserialization)
Employee, Leave and Recruitment Management System – Crew HRM Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Crew HRM <= 1.1.1 - Unauthenticated PHP Object Injection
Employee, Leave and Recruitment Management System – Crew HRM Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Employee, Leave and Recruitment Management System – Crew HRM Attack Surface
Shortcodes 1
WordPress Hooks 41
Scheduled Events 1
Maintenance & Trust
Employee, Leave and Recruitment Management System – Crew HRM Maintenance & Trust
Maintenance Signals
Community Trust
Employee, Leave and Recruitment Management System – Crew HRM Alternatives
Hiring Center
hiring-center
Create a powerful job portal and professional career page directly within WordPress. Simplify your recruitment workflow and manage job listings.
JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin
jobwp
Create a modern job board and career page on WordPress. Accept job listings, manage applications, and grow a recruitment platform.
Personio Integration Light
personio-integration-light
Import and display your positions from Personio directly on your website. Get full control over how they are displayed.
Cliptakes
cliptakes
Intuitive All-in-one Video Interview and Editing Plugin. Saving Recruiters Time and Capturing Talent, Masterfully.
Humera Job Board
humera-job-board
A simple and customizable job posting plugin with employer dashboard and frontend application form.
Employee, Leave and Recruitment Management System – Crew HRM Developer Profile
1 plugin · 200 total installs
How We Detect Employee, Leave and Recruitment Management System – Crew HRM
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hr-management/dist/hrm.js/wp-content/plugins/hr-management/dist/settings.js/wp-content/plugins/hr-management/dist/addons-page.js/wp-content/plugins/hr-management/dist/careers.js/wp-content/plugins/hr-management/dist/blocks-viewer.js/wp-content/plugins/hr-management/dist/libraries/translation-loader.js/wp-content/plugins/hr-management/dist/application-page.js/wp-content/plugins/hr-management/dist/settings-page.js/wp-content/plugins/hr-management/dist/hrm.js/wp-content/plugins/hr-management/dist/settings.js/wp-content/plugins/hr-management/dist/addons-page.js/wp-content/plugins/hr-management/dist/careers.js/wp-content/plugins/hr-management/dist/blocks-viewer.js/wp-content/plugins/hr-management/dist/libraries/translation-loader.js+2 morehr-management?ver=hr-management-recapcha-careers?ver=hr-management-recaptcha-settings?ver=hr-management-hrm?ver=hr-management-settings?ver=hr-management-addons-script?ver=hr-management-careers?ver=hr-management-blocks-viewer?ver=hr-management-translations?ver=HTML / DOM Fingerprints
crewhrm_containercrewhrm-titlecrewhrm-sub-titlecrewhrm-btncrewhrm-btn-primarycrewhrm-btn-secondarycrewhrm-btn-transparentcrewhrm-form-control+6 more<!-- Plugin Name: Crew HRM --><!-- Plugin URI: https://getcrewhrm.com/pricing/ --><!-- Description: Post jobs on your site and hire talent - all inside your website for free! --><!-- Author: Crew HRM -->+20 moredata-cylector="root"CrewHRM/wp-json/crewhrm/v1/wp-json/crewhrm/v1/jobs/wp-json/crewhrm/v1/departments/wp-json/crewhrm/v1/settings[crewhrm_jobs][crewhrm_careers_form][crewhrm_dashboard]