
Zij Indeed Jobs Security & Risk Analysis
wordpress.org/plugins/zij-indeed-jobsZij indeed jobs. Let you show the indeed jobs into your wordpress installation easily.
Is Zij Indeed Jobs Safe to Use in 2026?
Generally Safe
Score 92/100Zij Indeed Jobs has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the 'zij-indeed-jobs' v1.2 plugin appears to be a mixed bag, with some good practices evident but also significant areas for concern. On the positive side, the plugin has a remarkably small attack surface with no registered AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries are using prepared statements, which is an excellent practice for preventing SQL injection vulnerabilities. The absence of known CVEs and a clean vulnerability history also suggest a generally stable plugin in terms of past security issues.
However, the static analysis reveals several critical weaknesses. The most concerning is the extremely low percentage (27%) of properly escaped output. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or dynamic content might be rendered directly in the browser without proper sanitization. The complete lack of nonce checks and capability checks on any potential entry points (though the entry point count is zero, this indicates a lack of defense-in-depth if any were introduced) is also a significant concern, suggesting a reliance on the plugin's current limited functionality to remain secure rather than implementing robust authorization and integrity checks. The two external HTTP requests, while not inherently insecure, warrant scrutiny to ensure they do not introduce other vulnerabilities.
In conclusion, while the plugin exhibits some strong security fundamentals like prepared SQL statements and a minimal attack surface, the poor output escaping and absence of security checks on potential entry points represent significant vulnerabilities. The clean vulnerability history is a positive indicator, but the static analysis findings highlight immediate risks that need to be addressed to improve the overall security of the plugin.
Key Concerns
- Poor output escaping (27% properly escaped)
- No nonce checks on entry points
- No capability checks on entry points
- External HTTP requests present
Zij Indeed Jobs Security Vulnerabilities
Zij Indeed Jobs Release Timeline
Zij Indeed Jobs Code Analysis
Output Escaping
Zij Indeed Jobs Attack Surface
WordPress Hooks 4
Maintenance & Trust
Zij Indeed Jobs Maintenance & Trust
Maintenance Signals
Community Trust
Zij Indeed Jobs Alternatives
Simple Indeed Jobroll Widget
simple-indeed-jobroll-widget
Simple Indeed Jobroll Widget
Indeed Apply Shortcode
indeed-apply-shortcode
Easily accept job applications from any device, including mobile.
Indeed Jobs Shortcode
indeed-jobs-shortcode
This plugin allows users to add shortcode for indeed job API.
Jobs Ajax Feed Widget
jobs-ajax-feed-widget
Display job listings in an Ajax-powered RSS feed widget.
WP Indeed Post
wp-infeed-post
インフィード広告を挿入可能な新着記事表示プラグインです。
Zij Indeed Jobs Developer Profile
2 plugins · 20 total installs
How We Detect Zij Indeed Jobs
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zij-indeed-jobs/includes/style.cssHTML / DOM Fingerprints
zijindeed_job_wrapperzijindeed_job_titlezijindeed_field_wrapperzijindeed_titlezijindeed_valuezijindeed_snippetid="zijindeedjobs"id="zijindeed_apikey"id="zijindeed_category"id="zijindeed_location"id="zijindeed_jobtype"id="zijindeed_limit"