
All in one metadata Security & Risk Analysis
wordpress.org/plugins/all-in-one-metadataExtended Metadata for Wordpress and PressBooks.
Is All in one metadata Safe to Use in 2026?
Generally Safe
Score 85/100All in one metadata has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'all-in-one-metadata' v1.0.0 plugin exhibits a mixed security posture. While it lacks a history of known vulnerabilities and avoids dangerous functions, file operations, and external HTTP requests, several concerning aspects arise from the static analysis. A significant risk stems from the two AJAX handlers, both of which are unprotected by authentication checks, presenting a direct entry point for attackers. Furthermore, the taint analysis reveals a worrying number of flows with unsanitized paths, including four high-severity instances. This suggests that user-supplied data might not be adequately validated or sanitized before being processed, potentially leading to various injection attacks.
Despite the lack of documented CVEs, the presence of unprotected AJAX handlers and high-severity unsanitized taint flows indicates potential weaknesses that could be exploited. The plugin demonstrates some good practices, such as a reasonable percentage of SQL queries using prepared statements and the inclusion of nonce and capability checks. However, these are overshadowed by the direct exposure of AJAX endpoints and the identified taint issues. Overall, the plugin's security needs significant improvement to mitigate the identified risks, particularly concerning the unprotected AJAX endpoints and the handling of unsanitized data.
Key Concerns
- AJAX handlers without auth checks
- High severity taint flows with unsanitized paths
- Flows with unsanitized paths
- Bundled outdated library (Select2 v3.4.1)
All in one metadata Security Vulnerabilities
All in one metadata Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
All in one metadata Attack Surface
AJAX Handlers 2
WordPress Hooks 32
Maintenance & Trust
All in one metadata Maintenance & Trust
Maintenance Signals
Community Trust
All in one metadata Alternatives
Schema
schema
Get the next generation of Schema Structured Data to enhance your WordPress site presentation in Google search results.
Schema App Structured Data
schema-app-structured-data-for-schemaorg
Get Schema.org structured data for all pages, posts, categories and profile pages on activation. Use Schema App to customize any Schema Markup.
Really Rich Results – JSON-LD Structured Data (Google Rich Results)
really-rich-results
Really Rich Results quickly and accurately generates JSON-LD structured data schema markup with minimal effort required. Take advantage of Google' …
WP COVID-19 Schema
wp-covid-19-schema
WP COVID-19 Schema plugin adds a schema snippet in the WordPress websites of schools and hospitals to serve the specific purpose of announcements.
Schema & Structured Data for WP & AMP
schema-and-structured-data-for-wp
Schema & Structured Data adds Google Rich Snippets markup according to Schema.org guidelines to structure your site for SEO.
All in one metadata Developer Profile
9 plugins · 70 total installs
How We Detect All in one metadata
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/all-in-one-metadata/assets/css/all-in-one-metadata.css/wp-content/plugins/all-in-one-metadata/assets/js/all-in-one-metadata.js/wp-content/plugins/all-in-one-metadata/assets/js/all-in-one-metadata.jsall-in-one-metadata/assets/css/all-in-one-metadata.css?ver=all-in-one-metadata/assets/js/all-in-one-metadata.js?ver=