
VK Google Job Posting Manager Security & Risk Analysis
wordpress.org/plugins/vk-google-job-posting-managerThis plugin generates JSON-LD of your recruitment info which required to register Google Job Posting.
Is VK Google Job Posting Manager Safe to Use in 2026?
Generally Safe
Score 98/100VK Google Job Posting Manager has a strong security track record. Known vulnerabilities have been patched promptly.
The "vk-google-job-posting-manager" plugin v1.2.24 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices with 100% of SQL queries using prepared statements and a high rate of proper output escaping (98%). It also has a complete absence of known vulnerabilities that are currently unpatched, which is a significant strength. The static analysis reveals a very small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication or permission checks, and no unsanitized flows were identified in the taint analysis.
However, several areas warrant attention. The presence of a dangerous function like `unserialize` is a notable concern, as it can lead to arbitrary code execution if untrusted data is unserialized. While no capability checks were explicitly found in the static analysis, the limited attack surface might be masking potential privilege escalation vectors if specific functionalities are invoked without proper checks. The vulnerability history, though currently free of unpatched issues, shows a past of two medium-severity CVEs, both related to Cross-Site Scripting (XSS). This pattern suggests a historical susceptibility to input sanitization issues, even if the current version has addressed them. The external HTTP requests are also a potential area for attack if not handled securely.
In conclusion, while the plugin has made significant improvements and currently presents a low risk due to no unpatched vulnerabilities and a well-controlled attack surface, the lingering presence of `unserialize` and past XSS vulnerabilities necessitate continued vigilance. Developers should prioritize auditing the usage of `unserialize` for any potential deserialization vulnerabilities and maintain a proactive approach to security testing, especially concerning input validation.
Key Concerns
- Dangerous function: unserialize detected
- Past medium severity CVEs (2 total)
- External HTTP requests detected
VK Google Job Posting Manager Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
VK Google Job Posting Manager <= 1.2.23 - Authenticated (Author+) Stored Cross-Site Scripting via Job Description Field
VK Google Job Posting Manager <= 1.2.22 - Authenticated (Contributor+) Stored Cross-Site Scripting
VK Google Job Posting Manager Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
VK Google Job Posting Manager Attack Surface
WordPress Hooks 13
Maintenance & Trust
VK Google Job Posting Manager Maintenance & Trust
Maintenance Signals
Community Trust
VK Google Job Posting Manager Alternatives
Classic Editor
classic-editor
Enables the previous "classic" editor and the old-style Edit Post screen with TinyMCE, Meta Boxes, etc. Supports all plugins that extend this screen.
Starter Templates – AI-Powered Templates for Elementor & Gutenberg
astra-sites
The growing library of 300+ ready-to-use templates that work with all WordPress themes including Astra, Hello, OceanWP, GeneratePress and more
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
Advanced Editor Tools
tinymce-advanced
Extends and enhances the block editor (Gutenberg) and the classic editor (TinyMCE).
Spectra Gutenberg Blocks – Website Builder for the Block Editor
ultimate-addons-for-gutenberg
Power-up Gutenberg with advanced blocks for faster website creation. Build your WordPress website effortlessly using powerful building blocks!
VK Google Job Posting Manager Developer Profile
8 plugins · 241K total installs
How We Detect VK Google Job Posting Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/vk-google-job-posting-manager/assets/css/admin.cssvk-google-job-posting-manager/assets/css/admin.css?ver=HTML / DOM Fingerprints
vgjpmvgjpm_nonce