
Betta Boxes CMS Security & Risk Analysis
wordpress.org/plugins/betta-boxes-cmsCreate custom fields linked to posts, pages, or any custom post type with a point-and-click user interface.
Is Betta Boxes CMS Safe to Use in 2026?
Generally Safe
Score 85/100Betta Boxes CMS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "betta-boxes-cms" v1.1.5 plugin presents a mixed security picture. On the positive side, it has a remarkably small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, there is no known vulnerability history, which is a strong indicator of past security diligence. However, the static analysis reveals significant concerns within the code itself. The presence of six instances of the `unserialize` function is a major red flag, as it is notoriously difficult to use securely and can lead to Remote Code Execution vulnerabilities if not handled with extreme care and strict input validation. The low percentage of SQL queries using prepared statements (33%) and the very low rate of properly escaped output (7%) are also deeply concerning, suggesting potential SQL injection and Cross-Site Scripting (XSS) vulnerabilities respectively. The taint analysis showing all five analyzed flows with unsanitized paths further amplifies these concerns, even without a critical or high severity rating, as it indicates data is not being handled securely. The lack of any capability checks or nonce checks is also a weakness, especially given the use of `unserialize`.
Key Concerns
- Dangerous function: unserialize used
- Low percentage of prepared statements
- Very low rate of output escaping
- Taint flows with unsanitized paths found
- No nonce checks
- No capability checks
Betta Boxes CMS Security Vulnerabilities
Betta Boxes CMS Release Timeline
Betta Boxes CMS Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Betta Boxes CMS Attack Surface
WordPress Hooks 4
Maintenance & Trust
Betta Boxes CMS Maintenance & Trust
Maintenance Signals
Community Trust
Betta Boxes CMS Alternatives
PT Theme Addon
pt-theme-addon
Plugin to add team, testimonial portfolio and clients custom post type. Each post type has its widget and shortcode to use in theme.
Business Era Extension
business-era-extension
Plugin to extend features of Business Era Theme. This plugin registers custom post types, widgets and custom fields for the Business Era theme.
Theme Toolkit
theme-toolkit
Theme toolkit is a plugin to register custom post types, widgets and shortcodes to add additional feature and functionality to any WordPress theme.
C7 Form Builder
c7-form-builder
Provides an easy to use and powerful API for building forms that can be displayed, customized and saved any way you want.
Flow Fields
flow-fields
Flow Fields is a WordPress plugin that allows you to easily add custom fields to your posts, pages, and other custom post types.
Betta Boxes CMS Developer Profile
3 plugins · 1K total installs
How We Detect Betta Boxes CMS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/betta-boxes-cms/css/admin.css/wp-content/plugins/betta-boxes-cms/css/style.css/wp-content/plugins/betta-boxes-cms/js/admin.js/wp-content/plugins/betta-boxes-cms/js/frontend.js/wp-content/plugins/betta-boxes-cms/js/admin.js/wp-content/plugins/betta-boxes-cms/js/frontend.jsbetta-boxes-cms/css/admin.css?ver=betta-boxes-cms/css/style.css?ver=betta-boxes-cms/js/admin.js?ver=betta-boxes-cms/js/frontend.js?ver=HTML / DOM Fingerprints
betta-boxes-cmsdata-betta-boxes-cms-plugin-urlbettaBoxesCMSAdmin