
OTYS Plugin Security & Risk Analysis
wordpress.org/plugins/otys-jobs-applyThe OTYS Plugin makes your Wordpress website a proper recruiting website integrated with OTYS. The integration makes sure every step of the process is …
Is OTYS Plugin Safe to Use in 2026?
Generally Safe
Score 100/100OTYS Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "otys-jobs-apply" plugin v2.0.84 presents a mixed security posture. While it has no recorded CVEs and demonstrates good practices in SQL query sanitization (88% prepared) and output escaping (80%), several significant concerns arise from the static analysis. The plugin exposes 5 REST API routes without permission callbacks, creating a substantial attack surface that could be exploited by unauthenticated users. Additionally, the taint analysis revealed 2 high-severity flows with unsanitized paths, indicating potential for injection vulnerabilities if user-supplied data is not properly validated before use in critical operations. The complete absence of nonce checks on AJAX handlers is a major red flag, as it leaves these entry points vulnerable to Cross-Site Request Forgery (CSRF) attacks. The presence of the `assert` function is also noted as a potential, though less likely, source of concern if misused. Overall, the lack of historical vulnerabilities is positive, but the identified risks in the current version, particularly the unprotected REST API routes and lack of nonce checks, demand attention.
Key Concerns
- REST API routes without permission callbacks
- High severity taint flows with unsanitized paths
- No nonce checks on AJAX handlers
- Presence of dangerous function: assert
OTYS Plugin Security Vulnerabilities
OTYS Plugin Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
OTYS Plugin Attack Surface
REST API Routes 5
Shortcodes 10
WordPress Hooks 1
Scheduled Events 2
Maintenance & Trust
OTYS Plugin Maintenance & Trust
Maintenance Signals
Community Trust
OTYS Plugin Alternatives
Tamago-DB Job board
jobsearch
Tamago-DB Job Board integrates directly into the Tamago-DB ATS platform.
HRappka.pl
hrappka-pl
HRappka.pl plugin creates list of job offers and offers description pages with application link. * Account in HRappka.pl system is required for prope …
Iron gForce Lite
iron-gforce-lite
Integrate Greenhouse ATS into WordPress, streamlining recruitment. Display job listings from your Greenhouse job board.
Inesta Gravity Forms Recruitee Integration
inesta-integration-gravity-forms-recruitee
Integrates Gravity Forms with Recruitee ATS to send job applications directly to your Recruitee account.
Vacancy Lab
vacancy-lab
Add Vacancy Search and Candidate submissions that are powered by Vacancy Lab onto your Wordpress website.
OTYS Plugin Developer Profile
1 plugin · 200 total installs
How We Detect OTYS Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/otys-jobs-apply/assets/js/questionset.min.jshttps://www.google.com/recaptcha/api.jsotys-jobs-apply/assets/js/questionset.min.js?ver=HTML / DOM Fingerprints
data-grecaptcha-action/wp-json/otys/v1/interactions/