Spam and privacy
Spam
The application form is the only anonymous write path in the plugin, and Hire treats every request to it as hostile. The defences run in order, cheapest for the applicant first:
- A honeypot — a hidden field bots fill in and people don't. Rename it under Settings → Notifications; empty turns it off.
- A signed timestamp — a submission that arrives less than three seconds after the form was rendered is refused. Nobody types a name, an email and uploads a CV in three seconds.
- A rate limit — ten applications per IP per hour by default, counted in the cache against a
hash, so no addresses are stored to run it.
0turns it off. - Blocked email domains — disposable-address services, usually.
- A CAPTCHA, if you want one — reCAPTCHA v2 or v3, hCaptcha or Cloudflare Turnstile. Off by default, because it is a tax on disabled applicants and a third-party script on a page where somebody is typing their employment history.
Every refusal returns the same message — telling a script which check it failed is telling it how to pass — with one exception. The rate limit says so, because the person likeliest to hit it is a real applicant applying for several jobs in an hour, and "please try again" would send them straight back into it.
Uploads
See The application form: extension checked against your list, detected type checked against the extension, markup always refused, random-prefixed filenames, and CVs streamed through the control panel behind a permission. Put CVs in a private volume.
Retention (Pro)
Under Settings → Uploads & privacy, set how many days applications are kept. Past that, they are hard deleted — CV included — by a queued job that runs with Craft's garbage collection. A policy that leaves the data in the trash is not a policy.
The same thing on demand, with a look first:
php craft hire/applications/prune --days=365 --dry-run
php craft hire/applications/prune --days=365
Erasure
Deleting an application has a delete permanently option, which removes the application and its CV rather than sending them to the trash. That is what an erasure request needs.
IP addresses
Not recorded by default. It is useful for spam triage and it is personal data, and a plugin that collects it silently makes its user's privacy notice wrong. Turn on Record the applicant’s IP address under Settings → Uploads & privacy if you want it.
CSV export
Exports carry a UTF-8 byte-order mark, so Excel on Windows doesn't mangle accented names, and
formula injection is defused — a candidate who types =HYPERLINK(…) into a text box has not written
code that runs on the recruiter's machine. Phone numbers starting with + get a leading apostrophe
for the same reason; spreadsheets hide it.