
Any Custom Fields Security & Risk Analysis
wordpress.org/plugins/any-custom-fieldAny Custom fields provide the options to customize in wordpress front end website.
Is Any Custom Fields Safe to Use in 2026?
Generally Safe
Score 85/100Any Custom Fields has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "any-custom-field" v1.1 plugin exhibits a generally positive security posture with no known vulnerabilities or critical code signals. The complete absence of external HTTP requests, file operations, and SQL queries that are not properly prepared are strong indicators of good development practices. However, a significant concern arises from the taint analysis, which reveals one flow with unsanitized paths. While this is not classified as critical or high severity in this report, it represents a potential pathway for malicious input to be processed in an unsafe manner, necessitating further investigation.
Furthermore, the output escaping is notably poor, with only 4% of outputs being properly escaped. This could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is displayed without adequate sanitization. The plugin's vulnerability history being clean is a positive sign, suggesting maturity, but the presence of an unsanitized path and the low percentage of properly escaped outputs are weaknesses that temper the overall positive assessment. Improvements in output escaping and a thorough review of the identified unsanitized path are recommended to strengthen the plugin's security.
Key Concerns
- Taint flow with unsanitized paths
- Low percentage of properly escaped output
Any Custom Fields Security Vulnerabilities
Any Custom Fields Release Timeline
Any Custom Fields Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Any Custom Fields Attack Surface
WordPress Hooks 2
Maintenance & Trust
Any Custom Fields Maintenance & Trust
Maintenance Signals
Community Trust
Any Custom Fields Alternatives
General Options
general-options
This plugin allows the end user to upload a Header logo , Footer logo, Social media (facebook, twitter, skype, google+,instagram), Footer Content, Con …
Global Content Manager
global-content-manager
The simple and best plugin for making global sections WordPress.
Any Custom Fields Developer Profile
1 plugin · 10 total installs
How We Detect Any Custom Fields
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/any-custom-field/style.css/wp-content/plugins/any-custom-field/ajax.js/wp-content/plugins/any-custom-field/anycustomfield.jsstyle.cssajax.jsanycustomfield.jsany-custom-field/style.css?ver=any-custom-field/ajax.js?ver=any-custom-field/anycustomfield.js?ver=HTML / DOM Fingerprints
anc_hiddenopendc_hidden_nonceanc_site_logoblognameblogdescriptionanc_site_meta_title+18 morewp.hooks