Zij Indeed Jobs Security & Risk Analysis

wordpress.org/plugins/zij-indeed-jobs

Zij indeed jobs. Let you show the indeed jobs into your wordpress installation easily.

10 active installs v1.2 PHP + WP 3.0.1+ Updated Dec 9, 2024
indeedindeed-job-integrationindeed-jobs
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Zij Indeed Jobs Safe to Use in 2026?

Generally Safe

Score 92/100

Zij Indeed Jobs has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The security posture of the 'zij-indeed-jobs' v1.2 plugin appears to be a mixed bag, with some good practices evident but also significant areas for concern. On the positive side, the plugin has a remarkably small attack surface with no registered AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries are using prepared statements, which is an excellent practice for preventing SQL injection vulnerabilities. The absence of known CVEs and a clean vulnerability history also suggest a generally stable plugin in terms of past security issues.

However, the static analysis reveals several critical weaknesses. The most concerning is the extremely low percentage (27%) of properly escaped output. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or dynamic content might be rendered directly in the browser without proper sanitization. The complete lack of nonce checks and capability checks on any potential entry points (though the entry point count is zero, this indicates a lack of defense-in-depth if any were introduced) is also a significant concern, suggesting a reliance on the plugin's current limited functionality to remain secure rather than implementing robust authorization and integrity checks. The two external HTTP requests, while not inherently insecure, warrant scrutiny to ensure they do not introduce other vulnerabilities.

In conclusion, while the plugin exhibits some strong security fundamentals like prepared SQL statements and a minimal attack surface, the poor output escaping and absence of security checks on potential entry points represent significant vulnerabilities. The clean vulnerability history is a positive indicator, but the static analysis findings highlight immediate risks that need to be addressed to improve the overall security of the plugin.

Key Concerns

  • Poor output escaping (27% properly escaped)
  • No nonce checks on entry points
  • No capability checks on entry points
  • External HTTP requests present
Vulnerabilities
None known

Zij Indeed Jobs Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Zij Indeed Jobs Release Timeline

v1.1
v1.0
Code Analysis
Analyzed Apr 16, 2026

Zij Indeed Jobs Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
32
12 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

27% escaped44 total outputs
Attack Surface

Zij Indeed Jobs Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionwp_enqueue_scripts1.1/zij-indeed-jobs.php:154
actionwidgets_init1.1/zij-indeed-jobs.php:160
actionwp_enqueue_scriptszij-indeed-jobs.php:143
actionwidgets_initzij-indeed-jobs.php:149
Maintenance & Trust

Zij Indeed Jobs Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedDec 9, 2024
PHP min version
Downloads2K

Community Trust

Rating20/100
Number of ratings1
Active installs10
Developer Profile

Zij Indeed Jobs Developer Profile

Shoaib Rehmat

2 plugins · 20 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Zij Indeed Jobs

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zij-indeed-jobs/includes/style.css

HTML / DOM Fingerprints

CSS Classes
zijindeed_job_wrapperzijindeed_job_titlezijindeed_field_wrapperzijindeed_titlezijindeed_valuezijindeed_snippet
Data Attributes
id="zijindeedjobs"id="zijindeed_apikey"id="zijindeed_category"id="zijindeed_location"id="zijindeed_jobtype"id="zijindeed_limit"
FAQ

Frequently Asked Questions about Zij Indeed Jobs