Recooty AI Job Widget Security & Risk Analysis

wordpress.org/plugins/recooty-ai-job-widget

Embed Recooty job widget anywhere via shortcode.

0 active installs v1.0.0 PHP 7.0+ WP + Updated Oct 17, 2025
applicant-tracking-systemjob-listingjob-managementjob-widgetrecruiting-software
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Recooty AI Job Widget Safe to Use in 2026?

Generally Safe

Score 100/100

Recooty AI Job Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The recooy-ai-job-widget plugin version 1.0.0 demonstrates a strong security posture in several key areas. The static analysis reveals no dangerous functions, SQL queries are exclusively handled with prepared statements, and file operations and external HTTP requests are absent. Furthermore, the absence of any recorded vulnerabilities in its history is a significant positive indicator. However, there are areas that warrant attention and mitigation. The plugin lacks any nonce or capability checks, which can be a critical oversight for entry points like shortcodes. While the current attack surface is small and there are no explicit unprotected entry points *as identified by the analysis*, the absence of these fundamental security checks on the shortcode means that if it were to interact with sensitive data or functionality, it would be vulnerable to CSRF attacks. The high percentage of properly escaped output is good, but the 10% that is not escaped, although seemingly minor, could still be a vector for XSS if that output is derived from user input.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
  • Some output not properly escaped
Vulnerabilities
None known

Recooty AI Job Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Recooty AI Job Widget Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Recooty AI Job Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

90% escaped10 total outputs
Attack Surface

Recooty AI Job Widget Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[recooty_widget] recooty-widget.php:228
WordPress Hooks 4
actionwp_enqueue_scriptsrecooty-widget.php:26
actionadmin_menurecooty-widget.php:39
actionadmin_initrecooty-widget.php:48
actionadmin_enqueue_scriptsrecooty-widget.php:72
Maintenance & Trust

Recooty AI Job Widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 17, 2025
PHP min version7.0
Downloads203

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Recooty AI Job Widget Developer Profile

Recooty

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Recooty AI Job Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/recooty-ai-job-widget/admin-styles.css/wp-content/plugins/recooty-ai-job-widget/admin-script.js/wp-content/plugins/recooty-ai-job-widget/recooty-widget.iife.js
Script Paths
recooty-widget.iife.jsadmin-script.js
Version Parameters
recooty-widget.iife.js?ver=1.0admin-styles.css?ver=1.0.0admin-script.js?ver=1.0.0

HTML / DOM Fingerprints

CSS Classes
recooty-wraprecooty-headerrecooty-bodyrecooty-sidebarrecooty-mainrecooty-fieldrecooty-footerrecooty-guide-content+5 more
Data Attributes
id="recooty-settings-panel"id="recooty-guide-panel"id="nav-settings"id="nav-guide"name="recooty_widget_id"name="recooty_widget_language"+1 more
Shortcode Output
[recooty_widget]
FAQ

Frequently Asked Questions about Recooty AI Job Widget