Ultimate Member & Job Manager Security & Risk Analysis

wordpress.org/plugins/ultimate-member-job-manager

This plugin integrates WP Job Manager and its extensions into your Ultimate Member user profiles.

300 active installs v1.0.1.2 PHP 7.0+ WP 5.4+ Updated Apr 29, 2024
ultimate-memberultimate-member-job-managerwp-job-managerwp-job-manager-applicationswp-job-manager-bookmarks
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ultimate Member & Job Manager Safe to Use in 2026?

Generally Safe

Score 92/100

Ultimate Member & Job Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "ultimate-member-job-manager" v1.0.1.2 exhibits a generally strong security posture based on the provided static analysis. The complete absence of detectable AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code analysis indicates a lack of dangerous functions and file operations, and all SQL queries utilize prepared statements, which are excellent security practices. The presence of capability checks is also a positive sign for access control.

However, there are areas of concern. A notable weakness is the very low percentage of properly escaped output (17%). This suggests that user-supplied data or dynamic content might be rendered directly into the output without adequate sanitization, potentially leading to cross-site scripting (XSS) vulnerabilities. The absence of nonce checks across all entry points is another significant risk, as it leaves the application vulnerable to cross-site request forgery (CSRF) attacks if any protected actions were to be implemented later or are not explicitly captured in this analysis.

The plugin's vulnerability history is clean, with no known CVEs or past vulnerabilities. This is a positive indicator, suggesting a historically responsible development approach. Despite the clean history, the identified output escaping and nonce check weaknesses represent potential risks that should be addressed to maintain a robust security profile. The overall security is good due to a small attack surface and secure SQL handling, but the unescaped output and lack of nonce checks introduce a moderate level of risk.

Key Concerns

  • Low output escaping (17%)
  • 0 Nonce checks
Vulnerabilities
None known

Ultimate Member & Job Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Ultimate Member & Job Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
1 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

17% escaped6 total outputs
Attack Surface

Ultimate Member & Job Manager Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
filtersubmit_job_form_show_signintemplates\um-submit-job-form-content.php:14
actionwpultimate-member-components\wp-job-manager\shortcode-action-handler\class-um-wp-job-manager-shortcode-action-handler.php:25
actionwpultimate-member-components\wp-job-manager\shortcode-action-handler\class-um-wp-job-manager-shortcode-action-handler.php:57
actionwp_loadedultimate-member-components\wp-job-manager\shortcode-action-handler\class-um-wp-job-manager-shortcode-action-handler.php:90
filterjob_manager_pagination_argsultimate-member-components\wp-job-manager\um-wp-job-manager\um-wp-job-manager-functions.php:32
filterjob_manager_my_job_actionsultimate-member-components\wp-job-manager\um-wp-job-manager\um-wp-job-manager-functions.php:49
filterum_profile_tabsultimate-member-components\wp-job-manager\um-wp-job-manager\um-wp-job-manager-loader.php:20
actionum_profile_content_job_manager_defaultultimate-member-components\wp-job-manager\um-wp-job-manager\um-wp-job-manager-loader.php:21
actionum_profile_content_job_manager_job_dashboardultimate-member-components\wp-job-manager\um-wp-job-manager\um-wp-job-manager-loader.php:22
actionum_profile_content_job_manager_jobsultimate-member-components\wp-job-manager\um-wp-job-manager\um-wp-job-manager-loader.php:23
actionum_profile_content_job_manager_post_a_jobultimate-member-components\wp-job-manager\um-wp-job-manager\um-wp-job-manager-loader.php:24
actionum_profile_content_job_manager_my_bookmarksultimate-member-components\wp-job-manager\um-wp-job-manager\um-wp-job-manager-loader.php:25
actionum_profile_content_job_manager_job_alertsultimate-member-components\wp-job-manager\um-wp-job-manager\um-wp-job-manager-loader.php:26
filterjob_manager_get_dashboard_jobs_argsultimate-member-components\wp-job-manager\um-wp-job-manager\um-wp-job-manager-loader.php:67
filterjob_manager_get_dashboard_jobs_argsultimate-member-components\wp-job-manager\um-wp-job-manager\um-wp-job-manager-loader.php:73
actionplugins_loadedultimate-member-job-manager.php:35
actioninitultimate-member-job-manager.php:52
Maintenance & Trust

Ultimate Member & Job Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 29, 2024
PHP min version7.0
Downloads19K

Community Trust

Rating76/100
Number of ratings6
Active installs300
Developer Profile

Ultimate Member & Job Manager Developer Profile

Kishores

4 plugins · 420 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ultimate Member & Job Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ultimate-member-job-manager/ultimate-member-components/wp-job-manager/assets/css/um-wp-job-manager.css/wp-content/plugins/ultimate-member-job-manager/ultimate-member-components/wp-job-manager/assets/js/um-wp-job-manager.js
Script Paths
/wp-content/plugins/ultimate-member-job-manager/ultimate-member-components/wp-job-manager/assets/js/um-wp-job-manager.js
Version Parameters
ultimate-member-job-manager/ultimate-member-components/wp-job-manager/assets/css/um-wp-job-manager.css?ver=ultimate-member-job-manager/ultimate-member-components/wp-job-manager/assets/js/um-wp-job-manager.js?ver=

HTML / DOM Fingerprints

CSS Classes
um-wp-job-manager-field
FAQ

Frequently Asked Questions about Ultimate Member & Job Manager