
WP Jobs Security & Risk Analysis
wordpress.org/plugins/wp-jobsPost jobs on your WordPress site. User can apply and attach resume/CV for the jobs.
Is WP Jobs Safe to Use in 2026?
Mostly Safe
Score 84/100WP Jobs is generally safe to use though it hasn't been updated recently. 2 past CVEs were resolved. Keep it updated.
The "wp-jobs" plugin v2.3.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and includes a nonce check. The absence of file operations and external HTTP requests further reduces potential attack vectors. However, significant concerns arise from the code analysis, particularly the 59% rate of properly escaped outputs. This indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis reveals 3 flows with unsanitized paths, including 2 of high severity, suggesting potential for code execution or sensitive data compromise if these flows are exploitable by attackers. The plugin's vulnerability history, with 2 past CVEs (one high and one medium severity) related to XSS and SQL injection, reinforces these concerns. Although there are no currently unpatched CVEs, the recurring nature of these vulnerability types, coupled with the static analysis findings, suggests a need for improved input sanitization and output escaping practices. The plugin has a relatively small attack surface with no unprotected entry points, which is positive, but the internal code quality issues pose a significant threat.
Key Concerns
- High rate of unescaped output
- Taint flows with unsanitized paths (High severity)
- Past high severity SQL injection vulnerability
- Past medium severity XSS vulnerability
- Taint flows with unsanitized paths
WP Jobs Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP Jobs < 1.7 - Cross-Site Scripting
WP Jobs < 1.5 - SQL Injection
WP Jobs Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Jobs Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 13
Maintenance & Trust
WP Jobs Maintenance & Trust
Maintenance Signals
Community Trust
WP Jobs Alternatives
No alternatives data available yet.
WP Jobs Developer Profile
12 plugins · 613K total installs
How We Detect WP Jobs
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-jobs/css/bootstrap-responsive.min.css/wp-content/plugins/wp-jobs/css/bootstrap.min.css/wp-content/plugins/wp-jobs/css/styles.css/wp-content/plugins/wp-jobs/js/bootstrap.min.js/wp-content/plugins/wp-jobs/js/bootstrap.min.jswp-jobs/css/styles.css?ver=HTML / DOM Fingerprints
wp_jobs_designation