
NiceJob Security & Risk Analysis
wordpress.org/plugins/nicejobEasily add NiceJob Stories, Reviews, and Engage to your Wordpress site.
Is NiceJob Safe to Use in 2026?
Generally Safe
Score 97/100NiceJob has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The static analysis of the "nicejob" plugin v3.7.3 indicates a generally positive security posture with several good practices in place. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is a strong indicator of secure coding. The high percentage of properly escaped output also contributes to a reduced risk of Cross-Site Scripting (XSS) vulnerabilities. The presence of a nonce check, even if only one, is a positive sign. However, the complete lack of capability checks on any entry points (AJAX, REST API, shortcodes) is a significant concern, leaving all eight entry points potentially vulnerable to unauthorized access or manipulation if an attacker can find a way to trigger them without proper authorization. The taint analysis showing zero flows, while good, might be limited by the scope of the analysis itself and doesn't necessarily guarantee no vulnerabilities exist.
The vulnerability history of "nicejob" plugin is concerning, with a total of four medium-severity vulnerabilities recorded, primarily related to Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF). While there are no currently unpatched vulnerabilities, the pattern of past issues, especially common ones like XSS, suggests that the plugin has historically struggled with proper input sanitization and authorization, despite some improvements in the current version's output escaping. The last vulnerability being very recent (2024-12-11) highlights the ongoing need for vigilance and thorough security reviews.
In conclusion, while "nicejob" v3.7.3 demonstrates improvements in secure coding practices like prepared statements and output escaping, the complete absence of capability checks on its entry points and the historical prevalence of XSS and CSRF vulnerabilities present significant risks. The plugin's security is weakened by its potential for unauthorized execution of its features.
Key Concerns
- No capability checks on entry points
- History of 4 medium severity vulnerabilities
- History of XSS vulnerabilities
- History of CSRF vulnerabilities
NiceJob Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
NiceJob <= 3.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
NiceJob <= 3.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
NiceJob <= 3.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
NiceJob <= 3.6.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting
NiceJob Release Timeline
NiceJob Code Analysis
Output Escaping
NiceJob Attack Surface
Shortcodes 8
WordPress Hooks 5
Maintenance & Trust
NiceJob Maintenance & Trust
Maintenance Signals
Community Trust
NiceJob Alternatives
Reviewkit – Trustpilot Reviews Widget & Embed
gutensuite-reviewkit
Easily embed and showcase Trustpilot reviews on your WordPress site to build trust and boost conversions.
Broadly for WordPress
broadly
Broadly allows your business to easily communicate with your customers. Manage your online reputation and customer communications across SMS and email …
Starfish Review Generation & Marketing for WordPress
starfish-reviews
The best WordPress plugin for generating 5-star customer reviews on Google, Facebook, Tripadvisor, and many more platforms.
Boxyfy – Ultimate Affiliate Tool: Product Boxes, Price Alerts, Heatmap and AI
boxyfy
Build engaging product pages with dynamic rankings, product boxes, comparison tables, price charts, and real-time Amazon data retrieval.
WP Marketing
intellasphere
Fastest way to integrate WP Marketing widgets on a website, such as contact us, offers, events, promoter sign-ups, polls,surveys, feedback, newsletter …
NiceJob Developer Profile
1 plugin · 700 total installs
How We Detect NiceJob
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nicejob/css/main.css/wp-content/plugins/nicejob/js/sdk.min.js/wp-content/plugins/nicejob/js/nicework-showroom.js/wp-content/plugins/nicejob/js/nicework-widgets.jshttps://cdn.nicejob.co/js/sdk.min.jshttps://platform.nicejob.co/js/sdk.min.jshttps://app.nicejob.co/js/nicework-showroom.jshttps://reviews.nicejob.co/js/nicework-widgets.jshttps://app.nicejob.co/js/nicework-widgets.jsHTML / DOM Fingerprints
nicework-showroom-containernicework-review-feed-widgetnj-storiesdata-iddata-campaigndata-optiondata-styledata-filter-mediadata-media+4 moreNWDOMAINNWRDOMAIN<div class="nicework-showroom-container"></div><a class="nicework-review-feed-widget" href="<a class="nj-stories" href="