NiceJob Security & Risk Analysis

wordpress.org/plugins/nicejob

Easily add NiceJob Stories, Reviews, and Engage to your Wordpress site.

700 active installs v3.7.3 PHP 7.0+ WP 3.0.1+ Updated Feb 6, 2026
marketingnicejobreviewshowroomtrust-badge
97
A · Safe
CVEs total4
Unpatched0
Last CVEDec 11, 2024
Safety Verdict

Is NiceJob Safe to Use in 2026?

Generally Safe

Score 97/100

NiceJob has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

4 known CVEsLast CVE: Dec 11, 2024Updated 6mo ago
Risk Assessment

The static analysis of the "nicejob" plugin v3.7.3 indicates a generally positive security posture with several good practices in place. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is a strong indicator of secure coding. The high percentage of properly escaped output also contributes to a reduced risk of Cross-Site Scripting (XSS) vulnerabilities. The presence of a nonce check, even if only one, is a positive sign. However, the complete lack of capability checks on any entry points (AJAX, REST API, shortcodes) is a significant concern, leaving all eight entry points potentially vulnerable to unauthorized access or manipulation if an attacker can find a way to trigger them without proper authorization. The taint analysis showing zero flows, while good, might be limited by the scope of the analysis itself and doesn't necessarily guarantee no vulnerabilities exist.

The vulnerability history of "nicejob" plugin is concerning, with a total of four medium-severity vulnerabilities recorded, primarily related to Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF). While there are no currently unpatched vulnerabilities, the pattern of past issues, especially common ones like XSS, suggests that the plugin has historically struggled with proper input sanitization and authorization, despite some improvements in the current version's output escaping. The last vulnerability being very recent (2024-12-11) highlights the ongoing need for vigilance and thorough security reviews.

In conclusion, while "nicejob" v3.7.3 demonstrates improvements in secure coding practices like prepared statements and output escaping, the complete absence of capability checks on its entry points and the historical prevalence of XSS and CSRF vulnerabilities present significant risks. The plugin's security is weakened by its potential for unauthorized execution of its features.

Key Concerns

  • No capability checks on entry points
  • History of 4 medium severity vulnerabilities
  • History of XSS vulnerabilities
  • History of CSRF vulnerabilities
Vulnerabilities
4 published

NiceJob Security Vulnerabilities

CVEs by Year

4 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
4

4 total CVEs

CVE-2024-54318medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

NiceJob <= 3.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 11, 2024 Patched in 3.7.2 (9d)
CVE-2024-10887medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

NiceJob <= 3.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Nov 12, 2024 Patched in 3.7.2 (10d)
CVE-2024-44025medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

NiceJob <= 3.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 24, 2024 Patched in 3.6.5 (9d)
CVE-2024-44028medium · 6.1Cross-Site Request Forgery (CSRF)

NiceJob <= 3.6.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Sep 24, 2024 Patched in 3.6.5 (9d)
Code Analysis
Analyzed Mar 16, 2026

NiceJob Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
129 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

98% escaped132 total outputs
Attack Surface

NiceJob Attack Surface

Entry Points8
Unprotected0

Shortcodes 8

[nicejob-showroom] nicejob.php:48
[nicejob-review-feed] nicejob.php:86
[nicejob-stories] nicejob.php:203
[nicejob-badge] nicejob.php:263
[nicejob-engage] nicejob.php:329
[nicejob-lead] nicejob.php:400
[nicejob-review] nicejob.php:471
[nicejob-recommendation] nicejob.php:521
WordPress Hooks 5
actioninitnicejob.php:524
actionadmin_menunicejob.php:637
actionadmin_headnicejob.php:639
filtermce_external_pluginsnicejob.php:662
filtermce_buttonsnicejob.php:674
Maintenance & Trust

NiceJob Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.5
Last updatedFeb 6, 2026
PHP min version7.0
Downloads17K

Community Trust

Rating60/100
Number of ratings2
Active installs700
Developer Profile

NiceJob Developer Profile

nicejob

1 plugin · 700 total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
9 days
View full developer profile
Detection Fingerprints

How We Detect NiceJob

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nicejob/css/main.css/wp-content/plugins/nicejob/js/sdk.min.js/wp-content/plugins/nicejob/js/nicework-showroom.js/wp-content/plugins/nicejob/js/nicework-widgets.js
Script Paths
https://cdn.nicejob.co/js/sdk.min.jshttps://platform.nicejob.co/js/sdk.min.jshttps://app.nicejob.co/js/nicework-showroom.jshttps://reviews.nicejob.co/js/nicework-widgets.jshttps://app.nicejob.co/js/nicework-widgets.js

HTML / DOM Fingerprints

CSS Classes
nicework-showroom-containernicework-review-feed-widgetnj-stories
Data Attributes
data-iddata-campaigndata-optiondata-styledata-filter-mediadata-media+4 more
JS Globals
NWDOMAINNWRDOMAIN
Shortcode Output
<div class="nicework-showroom-container"></div><a class="nicework-review-feed-widget" href="<a class="nj-stories" href="
FAQ

Frequently Asked Questions about NiceJob