
Add Custom Fields to Media Security & Risk Analysis
wordpress.org/plugins/add-custom-fields-to-mediaAdd custom fields to media uploader and access them in template files. Great for copyrights, image meta etc.
Is Add Custom Fields to Media Safe to Use in 2026?
Generally Safe
Score 100/100Add Custom Fields to Media has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'add-custom-fields-to-media' plugin, version 2.0.4, exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and 100% proper output escaping are excellent security practices. Furthermore, the lack of identified taint flows and external HTTP requests mitigates common web application vulnerabilities. The presence of nonce checks, even without explicit capability checks on all entry points, suggests a conscious effort to prevent CSRF attacks.
However, the static analysis reveals a single shortcode as the only identified entry point, which is currently unprotected by explicit capability checks. While there are no critical or high-severity findings, and a clean vulnerability history, this unprotected shortcode represents a potential, albeit likely low, risk. Without further context on the shortcode's functionality, it's difficult to ascertain the exact impact, but it's a point that warrants consideration for a comprehensive security assessment.
In conclusion, the plugin demonstrates robust secure coding practices with no reported vulnerabilities or critical code signals. The primary area for potential improvement lies in ensuring all entry points, including the shortcode, are adequately protected by capability checks, which would further solidify its security. The plugin's strengths lie in its clean code and lack of known exploits.
Key Concerns
- Unprotected shortcode entry point
Add Custom Fields to Media Security Vulnerabilities
Add Custom Fields to Media Code Analysis
Output Escaping
Add Custom Fields to Media Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Add Custom Fields to Media Maintenance & Trust
Maintenance Signals
Community Trust
Add Custom Fields to Media Alternatives
EasyMedia – Increase Media Upload File Size | Role-Based Upload Limit | Increase Execution Time
wp-maximum-upload-file-size
EasyMedia - Increase the maximum upload file size limit to any value. Increase upload limit - upload large files effortlessly.
Add From Server
add-from-server
Add From Server is designed to help ease the pain of bad web hosts, allowing you to upload files via FTP or SSH and later import them into WordPress.
WP Extra File Types
wp-extra-file-types
Plugin to let you extend the list of allowed file types supported by the Wordpress Media Library
Easy SVG Support
easy-svg
This Plugin allows you to upload SVG Files into your Media library.
Media Sync
media-sync
Simple plugin to scan "uploads" directory and bring those files into Media Library.
Add Custom Fields to Media Developer Profile
9 plugins · 76K total installs
How We Detect Add Custom Fields to Media
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/add-custom-fields-to-media/css/add-custom-fields-to-media-admin.cssadd-custom-fields-to-media-admin.css?ver=