HireHive Job Plugin Security & Risk Analysis

wordpress.org/plugins/zartis-job-plugin

Easily add job listings and secure candidate management to your Wordpress site.

50 active installs v2.9.0 PHP + WP 2.9+ Updated Aug 3, 2021
careerjobjobsmanagervacancy
64
C · Use Caution
CVEs total1
Unpatched1
Last CVEJan 14, 2025
Safety Verdict

Is HireHive Job Plugin Safe to Use in 2026?

Use With Caution

Score 64/100

HireHive Job Plugin has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Jan 14, 2025Updated 4yr ago
Risk Assessment

The zartis-job-plugin v2.9.0 presents a mixed security posture. On the positive side, the static analysis shows no critical code vulnerabilities like dangerous functions, file operations, or external HTTP requests. All identified output is properly escaped, and there are no identified taint flows. The attack surface is relatively small, consisting of two shortcodes, and importantly, none of these entry points appear to be unprotected by default, nor are there unprotected AJAX handlers or REST API routes.

However, significant concerns arise from the plugin's vulnerability history. The presence of one unpatched medium severity CVE, specifically Cross-Site Scripting (XSS), is a critical red flag. This indicates a known security weakness that remains exploitable. Furthermore, the fact that the single SQL query within the code is not using prepared statements poses a risk of SQL injection, even if the attack surface for this is limited.

Overall, while the current code might appear clean of immediate exploitable flaws based on static analysis, the unpatched XSS vulnerability and the use of raw SQL queries without prepared statements are serious weaknesses. The plugin has a history of vulnerabilities, suggesting a potential lack of robust security development practices. Users should prioritize updating to a version that addresses the known CVE and be aware of the potential for SQL injection.

Key Concerns

  • Unpatched CVE
  • Raw SQL query without prepared statement
Vulnerabilities
1

HireHive Job Plugin Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-22746medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

HireHive Job Plugin <= 2.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jan 14, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

HireHive Job Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

100% escaped2 total outputs
Attack Surface

HireHive Job Plugin Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[zartis_jobs] Zartis_Job_Plugin.php:125
[hirehive_jobs] Zartis_Job_Plugin.php:126
WordPress Hooks 4
actioninitZartis_Job_Plugin.php:28
actionadmin_menuZartis_Job_Plugin.php:109
actionadmin_noticesZartis_Job_Plugin.php:114
filterscript_loader_tagZartis_Job_Plugin.php:207
Maintenance & Trust

HireHive Job Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.0
Last updatedAug 3, 2021
PHP min version
Downloads19K

Community Trust

Rating70/100
Number of ratings6
Active installs50
Developer Profile

HireHive Job Plugin Developer Profile

zartis

1 plugin · 50 total installs

69
trust score
Avg Security Score
64/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect HireHive Job Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zartis-job-plugin/css/zartis_wp.css/wp-content/plugins/zartis-job-plugin/js/zartis_functions.js/wp-content/plugins/zartis-job-plugin/css/hirehive-widget-styles.css
Script Paths
https://cdn1.hirehive.com/web-components/wp/job-listings/@latest/dist/hirehive-job-listing/hirehive-job-listing.esm.jshttps://cdn1.hirehive.com/web-components/wp/job-listings/@latest/dist/hirehive-job-listing/hirehive-job-listing.js

HTML / DOM Fingerprints

HTML Comments
<!-- Jobs for - <!-- Chosen group - <!-- Category - <!-- Version - 2.9.0 -->+1 more
Data Attributes
subdomaingroup-bytakeskipcountry-codecategory
JS Globals
HireHive_Message
Shortcode Output
<hirehive-job-listing<div slot="no-results">
FAQ

Frequently Asked Questions about HireHive Job Plugin