
HireHive Job Plugin Security & Risk Analysis
wordpress.org/plugins/zartis-job-pluginEasily add job listings and secure candidate management to your Wordpress site.
Is HireHive Job Plugin Safe to Use in 2026?
Use With Caution
Score 64/100HireHive Job Plugin has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The zartis-job-plugin v2.9.0 presents a mixed security posture. On the positive side, the static analysis shows no critical code vulnerabilities like dangerous functions, file operations, or external HTTP requests. All identified output is properly escaped, and there are no identified taint flows. The attack surface is relatively small, consisting of two shortcodes, and importantly, none of these entry points appear to be unprotected by default, nor are there unprotected AJAX handlers or REST API routes.
However, significant concerns arise from the plugin's vulnerability history. The presence of one unpatched medium severity CVE, specifically Cross-Site Scripting (XSS), is a critical red flag. This indicates a known security weakness that remains exploitable. Furthermore, the fact that the single SQL query within the code is not using prepared statements poses a risk of SQL injection, even if the attack surface for this is limited.
Overall, while the current code might appear clean of immediate exploitable flaws based on static analysis, the unpatched XSS vulnerability and the use of raw SQL queries without prepared statements are serious weaknesses. The plugin has a history of vulnerabilities, suggesting a potential lack of robust security development practices. Users should prioritize updating to a version that addresses the known CVE and be aware of the potential for SQL injection.
Key Concerns
- Unpatched CVE
- Raw SQL query without prepared statement
HireHive Job Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
HireHive Job Plugin <= 2.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
HireHive Job Plugin Code Analysis
SQL Query Safety
Output Escaping
HireHive Job Plugin Attack Surface
Shortcodes 2
WordPress Hooks 4
Maintenance & Trust
HireHive Job Plugin Maintenance & Trust
Maintenance Signals
Community Trust
HireHive Job Plugin Alternatives
Job Postings
job-postings
WordPress plugin that make it easy to add job postings to your company’s website in a structured way.
Simple Job Board
simple-job-board
job board plugin for job listings, managing applicants, applications, categories, job types, taxonomies, career page, job openings, and recruiters
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website
wp-job-portal
A smart, AI-powered job board plugin for WordPress. Build modern recruitment platforms with job listings, resume search, and intelligent matching.
JobPass
jobpass
Publiez vos offres d'emploi sur votre site web et permettez à vos candidats d'envoyer leur dossier de candidature complet en 1 clic grâce à …
WP Job Manager
wp-job-manager
Create a careers page for your company website, or build a public job board for your community.
HireHive Job Plugin Developer Profile
1 plugin · 50 total installs
How We Detect HireHive Job Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zartis-job-plugin/css/zartis_wp.css/wp-content/plugins/zartis-job-plugin/js/zartis_functions.js/wp-content/plugins/zartis-job-plugin/css/hirehive-widget-styles.csshttps://cdn1.hirehive.com/web-components/wp/job-listings/@latest/dist/hirehive-job-listing/hirehive-job-listing.esm.jshttps://cdn1.hirehive.com/web-components/wp/job-listings/@latest/dist/hirehive-job-listing/hirehive-job-listing.jsHTML / DOM Fingerprints
<!-- Jobs for - <!-- Chosen group - <!-- Category - <!-- Version - 2.9.0 -->+1 moresubdomaingroup-bytakeskipcountry-codecategoryHireHive_Message<hirehive-job-listing<div slot="no-results">