Widget Offres Security & Risk Analysis

wordpress.org/plugins/widget-offres-demploi-pole-emploi

Intégrez une carte interactive des offres de France Travail

60 active installs v0.2.46 PHP 7.0+ WP 4.1+ Updated Dec 4, 2025
france-travailoffres-emploipole-emploiwidget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Widget Offres Safe to Use in 2026?

Generally Safe

Score 100/100

Widget Offres has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "widget-offres-demploi-pole-emploi" plugin version 0.2.46 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a clean vulnerability history are strong indicators of good development practices and diligent maintenance regarding known security issues.

However, the static analysis reveals a few areas for improvement. While the overall attack surface is small and no unprotected entry points were identified, the lack of nonce checks on the single shortcode is a concern. This could potentially be exploited if the shortcode processes user-supplied data without proper validation. Additionally, while the code signals indicate proper handling of SQL queries and a good percentage of output escaping, a portion of the output (33%) is not properly escaped, presenting a potential cross-site scripting (XSS) risk if user-controlled data is involved in those outputs.

In conclusion, the plugin benefits from a lack of historical vulnerabilities and a generally secure approach to sensitive operations like SQL queries. The primary weaknesses lie in the potential for missing nonce checks on the shortcode and the unescaped output. Addressing these points would significantly strengthen the plugin's security.

Key Concerns

  • No nonce checks on shortcode
  • Unescaped output present
Vulnerabilities
None known

Widget Offres Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Widget Offres Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
10 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

67% escaped15 total outputs
Attack Surface

Widget Offres Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[widget-offres-ft] widget-offres.php:579
WordPress Hooks 2
actionadmin_menuwidget-offres.php:28
actionadmin_initwidget-offres.php:543
Maintenance & Trust

Widget Offres Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedDec 4, 2025
PHP min version7.0
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs60
Developer Profile

Widget Offres Developer Profile

teampoleemploiio

1 plugin · 60 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Widget Offres

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/widget-offres-demploi-pole-emploi/bootstrap-icons.css/wp-content/plugins/widget-offres-demploi-pole-emploi/logo.png

HTML / DOM Fingerprints

CSS Classes
peio-criteriapeio-eyeblocpeio-identifiantspeio-identifiants-inputpeio-parametres-techniquesswitchslider+3 more
Data Attributes
id="paramsWidget"id="peio-parametres-techniques"id="logo-peio"id="logo-peio2"
FAQ

Frequently Asked Questions about Widget Offres