
Simple Indeed Jobroll Widget Security & Risk Analysis
wordpress.org/plugins/simple-indeed-jobroll-widgetSimple Indeed Jobroll Widget
Is Simple Indeed Jobroll Widget Safe to Use in 2026?
Generally Safe
Score 85/100Simple Indeed Jobroll Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The `simple-indeed-jobroll-widget` plugin v1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and has no recorded vulnerability history, suggesting a lack of publicly disclosed security flaws. The attack surface also appears to be minimal, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events. However, there are significant concerns within the code itself.
The presence of the `create_function` function is a major red flag. This function is deprecated and notoriously difficult to secure, often leading to arbitrary code execution vulnerabilities if user-supplied input can influence its execution context. Furthermore, the plugin suffers from severely lacking output escaping, with only 11% of outputs being properly escaped. This opens the door to cross-site scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed in a user's browser.
The absence of nonce checks and capability checks, coupled with the lack of proper output escaping, creates a scenario where even a small attack surface (if it were to exist beyond what's reported) could be leveraged for malicious purposes. The total lack of taint analysis results is also unusual and might indicate that the analysis tools were not comprehensive enough to detect potential flows, or that the plugin is so simple that no complex data flows were identified. Overall, while the plugin has a clean history, the identified code-level weaknesses, particularly `create_function` and poor output escaping, present a notable risk.
Key Concerns
- Dangerous function detected (create_function)
- Low output escaping rate (11%)
- Missing nonce checks
- Missing capability checks
Simple Indeed Jobroll Widget Security Vulnerabilities
Simple Indeed Jobroll Widget Release Timeline
Simple Indeed Jobroll Widget Code Analysis
Dangerous Functions Found
Output Escaping
Simple Indeed Jobroll Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
Simple Indeed Jobroll Widget Maintenance & Trust
Maintenance Signals
Community Trust
Simple Indeed Jobroll Widget Alternatives
career builder job search plugin
career-builder-jobsearch
Simple widget which fetch jobs from careerbuilder.com api .
Zij Indeed Jobs
zij-indeed-jobs
Zij indeed jobs. Let you show the indeed jobs into your wordpress installation easily.
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Simple Indeed Jobroll Widget Developer Profile
2 plugins · 20 total installs
How We Detect Simple Indeed Jobroll Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-indeed-jobroll-widget/style.css/wp-content/plugins/simple-indeed-jobroll-widget/script.jshttp://www.indeed.com/ads/jobroll-widget-v3.jsHTML / DOM Fingerprints
indJobContentindeed_widget_wrapperindeed_widget_headerindeed_search_wrapperindeed_search_footerindeed_linkcompany_locationindpubnumind_pubind_elind_pfind_qind_lind_chnl+4 more