
ACTUS Xfields Security & Risk Analysis
wordpress.org/plugins/actus-xfieldsEasy way to add custom data to your website. Create custom fields for your pages and posts, or global options for your website.
Is ACTUS Xfields Safe to Use in 2026?
Generally Safe
Score 85/100ACTUS Xfields has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'actus-xfields' plugin v1.0.3 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is highly commendable. Furthermore, the plugin demonstrates good practices with a high percentage of properly escaped output, the presence of nonce checks on all identified AJAX handlers, and capability checks on a significant portion of its entry points. The taint analysis reveals no unsanitized paths, indicating a low risk of injection vulnerabilities.
However, despite the generally positive findings, there are areas for improvement. While all AJAX handlers have nonce checks, only 3 out of 6 have explicit capability checks. This leaves a portion of the attack surface potentially vulnerable to privilege escalation if an authenticated user with insufficient privileges can exploit these handlers. The lack of any recorded historical vulnerabilities is a positive sign, suggesting a mature and well-maintained codebase, but it's crucial to maintain this vigilance. Overall, the plugin is well-built with robust security mechanisms in place, but a minor enhancement in capability checks for all AJAX handlers would further strengthen its security.
Key Concerns
- Capability checks missing on 3 AJAX handlers
ACTUS Xfields Security Vulnerabilities
ACTUS Xfields Code Analysis
Output Escaping
Data Flow Analysis
ACTUS Xfields Attack Surface
AJAX Handlers 6
WordPress Hooks 11
Maintenance & Trust
ACTUS Xfields Maintenance & Trust
Maintenance Signals
Community Trust
ACTUS Xfields Alternatives
JSM Show Post Metadata
jsm-show-post-meta
Show post metadata (aka custom fields) in a metabox when editing posts / pages - a great tool for debugging issues with post metadata.
JSM Show User Metadata
jsm-show-user-meta
Show user metadata in a metabox when editing users - a great tool for debugging issues with user metadata.
Profile Extra Fields by BestWebSoft
profile-extra-fields
Add custom fields to WordPress user profiles and WooCommerce forms. Easily collect and display extra user information using a simple interface.
JSM Show Order Metadata for WooCommerce HPOS
jsm-show-order-meta
Show WooCommerce order metadata in a metabox when editing HPOS orders - a great tool for debugging issues with HPOS order metadata.
CFS Custom Category Fields
cfs-custom-category-fields
A Custom Field Suite Addon that provides custom meta data for categories and custom taxonomies.
ACTUS Xfields Developer Profile
3 plugins · 30 total installs
How We Detect ACTUS Xfields
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/actus-xfields/css/actus-admin.css/wp-content/plugins/actus-xfields/css/actus-xf-admin.css/wp-content/plugins/actus-xfields/js/actus-xf-admin.js/wp-content/plugins/actus-xfields/js/actus-xf-admin-events.js/wp-content/plugins/actus-xfields/js/actus-xf-admin.js/wp-content/plugins/actus-xfields/js/actus-xf-admin-events.jsactus-xfields/css/actus-admin.css?ver=actus-xfields/css/actus-xf-admin.css?ver=actus-xfields/js/actus-xf-admin.js?ver=actus-xfields/js/actus-xf-admin-events.js?ver=HTML / DOM Fingerprints
actus-settingsactus-xf-adminactus-admin-headeractus-xf-admin-headeractus-admin-header-logoactus-admin-header-titleactus-admin-mainactus-xf-admin-mainactusXFparams