Jobs Portal – Job & Career Manager Security & Risk Analysis

wordpress.org/plugins/jobs-portal

A powerful and robust plugin to create and manage job portal on your WordPress website where recruiter can post job requirements.

30 active installs v4.2 PHP + WP + Updated Feb 23, 2026
career-managerjob-listingjob-managerjob-portaljob-posting
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Jobs Portal – Job & Career Manager Safe to Use in 2026?

Generally Safe

Score 100/100

Jobs Portal – Job & Career Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "jobs-portal" plugin version 4.2 exhibits a mixed security posture. While the absence of known CVEs and a strong percentage of properly escaped outputs are positive indicators, significant concerns arise from its attack surface and a lack of robust authorization checks. The analysis reveals a substantial number of AJAX handlers (7) with no authentication or capability checks, presenting a direct pathway for unauthorized actions if malicious input is provided. The taint analysis is clean, indicating no critical or high-severity unsanitized flows, which is a strong point. However, the presence of SQL queries that are not consistently prepared (45% not using prepared statements) is a significant risk for potential SQL injection vulnerabilities, especially when combined with unprotected AJAX endpoints.

The plugin's vulnerability history is clean, with no recorded CVEs. This could suggest good development practices or simply a lack of public disclosure, but it does not negate the risks identified in the static analysis. The overall picture is a plugin with some good security fundamentals (escaping, no dangerous functions) but with critical gaps in input validation and authorization, particularly concerning its AJAX endpoints and database interactions. Addressing the unprotected AJAX handlers and ensuring all SQL queries are properly prepared are paramount to improving its security.

Key Concerns

  • Unprotected AJAX handlers
  • SQL queries without prepared statements
Vulnerabilities
None known

Jobs Portal – Job & Career Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Jobs Portal – Job & Career Manager Release Timeline

v4.2Current
v4.1
v4.0
v3.9
v3.8
v3.7
v3.6
v3.5
v3.4
v3.3
v3.2
v3.1
v3.0
v2.9
v2.8
v2.7
v2.6
v2.5
v2.4
v2.3
Code Analysis
Analyzed Mar 16, 2026

Jobs Portal – Job & Career Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
6
5 prepared
Unescaped Output
35
430 escaped
Nonce Checks
8
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

45% prepared11 total queries

Output Escaping

92% escaped465 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

3 flows
<weblizar_job_applications> (admin\inc\views\weblizar_job_applications.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
7 unprotected

Jobs Portal – Job & Career Manager Attack Surface

Entry Points9
Unprotected7

AJAX Handlers 7

noprivwp_ajax_weblizar-signuppublic\public.php:43
noprivwp_ajax_weblizar-loginpublic\public.php:46
authwp_ajax_weblizar-accountpublic\public.php:49
authwp_ajax_weblizar-cvpublic\public.php:52
authwp_ajax_weblizar-cv-updatepublic\public.php:55
authwp_ajax_weblizar-cv-deletepublic\public.php:58
authwp_ajax_weblizar-job-applypublic\public.php:61

Shortcodes 2

[job_portal] public\public.php:36
[job_portal_account] public\public.php:37
WordPress Hooks 25
actionadd_meta_boxesadmin\admin.php:15
actionadd_meta_boxesadmin\admin.php:16
actionadmin_enqueue_scriptsadmin\admin.php:19
actionadmin_enqueue_scriptsadmin\admin.php:20
actionsave_postadmin\admin.php:23
actionsave_postadmin\admin.php:24
actionbefore_delete_postadmin\admin.php:27
actionpost_edit_form_tagadmin\admin.php:30
filterenter_title_hereadmin\admin.php:33
filtermanage_candidate_posts_columnsadmin\admin.php:36
actionadmin_menuadmin\admin.php:39
actionadmin_initadmin\admin.php:42
actionadmin_noticesadmin\admin.php:45
actionplugins_loadedpublic\public.php:13
actioninitpublic\public.php:16
actioninitpublic\public.php:17
actioninitpublic\public.php:20
actioninitpublic\public.php:23
actioninitpublic\public.php:24
actioninitpublic\public.php:25
actioninitpublic\public.php:26
actioninitpublic\public.php:27
filtersingle_templatepublic\public.php:30
actionwp_enqueue_scriptspublic\public.php:33
actionwp_enqueue_scriptspublic\public.php:40
Maintenance & Trust

Jobs Portal – Job & Career Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 23, 2026
PHP min version
Downloads9K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Jobs Portal – Job & Career Manager Developer Profile

Weblizar - WordPress Themes & Plugin

26 plugins · 56K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
952 days
View full developer profile
Detection Fingerprints

How We Detect Jobs Portal – Job & Career Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jobs-portal/assets/css/banner.css

HTML / DOM Fingerprints

CSS Classes
wb_plugin_featurewb_plugin_feature_bannerweblizarweblizar_candidate_accountweblizar_candidate_personal
Data Attributes
id="weblizar_candidate_account"id="weblizar_candidate_personal"
FAQ

Frequently Asked Questions about Jobs Portal – Job & Career Manager