
WP Job Manager – Company Profiles Security & Risk Analysis
wordpress.org/plugins/wp-job-manager-companiesOutputs a list of all companies that have submitted jobs with links to their listings and profile.
Is WP Job Manager – Company Profiles Safe to Use in 2026?
Generally Safe
Score 91/100WP Job Manager – Company Profiles has a strong security track record. Known vulnerabilities have been patched promptly.
The "wp-job-manager-companies" v1.8 plugin exhibits a generally positive security posture with its static analysis results. A notable strength is the complete absence of dangerous functions, file operations, and external HTTP requests, which significantly reduces the attack surface. Furthermore, all identified output points are properly escaped, and there are no critical or high severity taint flows detected, indicating good practices in preventing common web vulnerabilities like Cross-Site Scripting and data leaks.
However, there are areas of concern that warrant attention. The plugin has a single known medium severity CVE related to Cross-Site Scripting that is currently patched, but its history suggests past vulnerabilities of this type. The most significant code-level concern is the presence of a SQL query that does not utilize prepared statements, which could potentially be vulnerable to SQL injection if not handled meticulously within the application logic. Additionally, the lack of any nonce or capability checks across its entry points, particularly for its single shortcode, leaves it open to potential unauthorized actions or information disclosure if the shortcode's functionality is sensitive.
In conclusion, while the plugin has demonstrated improvements by patching its known vulnerabilities and implementing proper output escaping, the un-prepared SQL query and the absence of authentication/authorization checks on its entry points present a tangible risk. The history of a past XSS vulnerability, although patched, highlights the importance of ongoing vigilance and robust security measures.
Key Concerns
- SQL queries without prepared statements
- Missing nonce checks on entry points
- Missing capability checks on entry points
WP Job Manager – Company Profiles Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Job Manager – Company Profiles <= 1.7 - Reflected Cross-Site Scripting
WP Job Manager – Company Profiles Code Analysis
SQL Query Safety
Output Escaping
WP Job Manager – Company Profiles Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
WP Job Manager – Company Profiles Maintenance & Trust
Maintenance Signals
Community Trust
WP Job Manager – Company Profiles Alternatives
MAS Companies For WP Job Manager
mas-wp-job-manager-company
MAS Companies For WP Job Manager is a free plugin that allow you to manage companies from the WordPress admin panel, and allow employers to post their …
WP Job Openings – Job Listing, Career Page and Recruitment Plugin
wp-job-openings
WP Job Openings plugin is the most simple yet powerful plugin for setting up a job listing page for your WordPress website.
Simple Job Board
simple-job-board
job board plugin for job listings, managing applicants, applications, categories, job types, taxonomies, career page, job openings, and recruiters
Regions for WP Job Manager
wp-job-manager-locations
Add predefined regions to WP Job Manager submission form.
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website
wp-job-portal
A smart, AI-powered job board plugin for WordPress. Build modern recruitment platforms with job listings, resume search, and intelligent matching.
WP Job Manager – Company Profiles Developer Profile
10 plugins · 23K total installs
How We Detect WP Job Manager – Company Profiles
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-job-manager-companies/wp-job-manager-companies.phpHTML / DOM Fingerprints
companies-overviewcompany-groupcompany-lettercompany-namedata-masonrywp_job_manager_companies<div class="company-letters"><a href="#<ul class="companies-overview"><li class="company-group">