WP Job Manager – Company Profiles Security & Risk Analysis

wordpress.org/plugins/wp-job-manager-companies

Outputs a list of all companies that have submitted jobs with links to their listings and profile.

3K active installs v1.8 PHP + WP 4.4+ Updated Nov 28, 2024
companiescompany-listjobjob-listing
91
A · Safe
CVEs total1
Unpatched0
Last CVEDec 3, 2024
Safety Verdict

Is WP Job Manager – Company Profiles Safe to Use in 2026?

Generally Safe

Score 91/100

WP Job Manager – Company Profiles has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Dec 3, 2024Updated 1yr ago
Risk Assessment

The "wp-job-manager-companies" v1.8 plugin exhibits a generally positive security posture with its static analysis results. A notable strength is the complete absence of dangerous functions, file operations, and external HTTP requests, which significantly reduces the attack surface. Furthermore, all identified output points are properly escaped, and there are no critical or high severity taint flows detected, indicating good practices in preventing common web vulnerabilities like Cross-Site Scripting and data leaks.

However, there are areas of concern that warrant attention. The plugin has a single known medium severity CVE related to Cross-Site Scripting that is currently patched, but its history suggests past vulnerabilities of this type. The most significant code-level concern is the presence of a SQL query that does not utilize prepared statements, which could potentially be vulnerable to SQL injection if not handled meticulously within the application logic. Additionally, the lack of any nonce or capability checks across its entry points, particularly for its single shortcode, leaves it open to potential unauthorized actions or information disclosure if the shortcode's functionality is sensitive.

In conclusion, while the plugin has demonstrated improvements by patching its known vulnerabilities and implementing proper output escaping, the un-prepared SQL query and the absence of authentication/authorization checks on its entry points present a tangible risk. The history of a past XSS vulnerability, although patched, highlights the importance of ongoing vigilance and robust security measures.

Key Concerns

  • SQL queries without prepared statements
  • Missing nonce checks on entry points
  • Missing capability checks on entry points
Vulnerabilities
1

WP Job Manager – Company Profiles Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-6978medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Job Manager – Company Profiles <= 1.7 - Reflected Cross-Site Scripting

Dec 3, 2024 Patched in 1.8 (1d)
Code Analysis
Analyzed Mar 16, 2026

WP Job Manager – Company Profiles Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
0
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

100% escaped5 total outputs
Attack Surface

WP Job Manager – Company Profiles Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[job_manager_companies] wp-job-manager-companies.php:90
WordPress Hooks 7
filterpre_get_document_titlewp-job-manager-companies.php:92
actiongenerate_rewrite_ruleswp-job-manager-companies.php:94
filterquery_varswp-job-manager-companies.php:95
filterpre_get_postswp-job-manager-companies.php:96
actiontemplate_redirectwp-job-manager-companies.php:97
actionplugins_loadedwp-job-manager-companies.php:99
actionplugins_loadedwp-job-manager-companies.php:355
Maintenance & Trust

WP Job Manager – Company Profiles Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 28, 2024
PHP min version
Downloads158K

Community Trust

Rating40/100
Number of ratings18
Active installs3K
Developer Profile

WP Job Manager – Company Profiles Developer Profile

Astoundify

10 plugins · 23K total installs

81
trust score
Avg Security Score
90/100
Avg Patch Time
31 days
View full developer profile
Detection Fingerprints

How We Detect WP Job Manager – Company Profiles

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-job-manager-companies/wp-job-manager-companies.php

HTML / DOM Fingerprints

CSS Classes
companies-overviewcompany-groupcompany-lettercompany-name
Data Attributes
data-masonry
JS Globals
wp_job_manager_companies
Shortcode Output
<div class="company-letters"><a href="#<ul class="companies-overview"><li class="company-group">
FAQ

Frequently Asked Questions about WP Job Manager – Company Profiles