
Bonzer Custom Fields Creator Security & Risk Analysis
wordpress.org/plugins/bonzer-custom-fieldsCreate wide array of input fields at various location in the admin panel.
Is Bonzer Custom Fields Creator Safe to Use in 2026?
Generally Safe
Score 100/100Bonzer Custom Fields Creator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bonzer-custom-fields" v1.1.1 plugin exhibits a mixed security posture. On one hand, it demonstrates good practices in its SQL query handling, with 100% of queries using prepared statements, and it has no recorded vulnerability history, suggesting a potentially stable and well-maintained codebase. However, significant concerns arise from its attack surface and code analysis.
The plugin exposes a substantial attack surface through 6 AJAX handlers, with an alarming 5 of them lacking authentication checks. This means potentially sensitive operations could be triggered by any visitor to the site. Furthermore, the taint analysis reveals 4 flows with unsanitized paths, which, while not currently classified as critical or high severity, indicate potential pathways for malicious input to reach sensitive functions or the filesystem. The presence of `shell_exec` is a critical function that, when combined with unsanitized inputs, can lead to remote code execution. The output escaping is also problematic, with nearly half of the outputs not being properly escaped, increasing the risk of cross-site scripting (XSS) vulnerabilities.
While the lack of known CVEs is positive, it should not be relied upon as the sole indicator of security. The significant number of unprotected entry points and the concerning taint analysis results present immediate risks that need to be addressed. The plugin has strengths in its SQL handling and lack of history, but these are overshadowed by the present, identifiable vulnerabilities in its attack surface and code execution/output handling.
Key Concerns
- AJAX handlers without authentication
- Unsanitized paths in taint analysis
- Dangerous function: shell_exec
- Low output escaping percentage
- Missing capability checks
- Missing nonce checks on AJAX
Bonzer Custom Fields Creator Security Vulnerabilities
Bonzer Custom Fields Creator Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Data Flow Analysis
Bonzer Custom Fields Creator Attack Surface
AJAX Handlers 6
WordPress Hooks 15
Maintenance & Trust
Bonzer Custom Fields Creator Maintenance & Trust
Maintenance Signals
Community Trust
Bonzer Custom Fields Creator Alternatives
Effortless Custom Fields :: ECF
effortless-custom-fields
World’s least confusing custom fields plugin.
CubeWP Framework
cubewp-framework
CubeWP is an end-to-end dynamic content framework for WordPress to help you shrink time and cut cost of development up to 90%.
PT Theme Addon
pt-theme-addon
Plugin to add team, testimonial portfolio and clients custom post type. Each post type has its widget and shortcode to use in theme.
Meta Content
meta
A meta box which helps us to add content or scripts to any part of the website, on each individual post/page. Easy to Implement with Shortcode.
Business Era Extension
business-era-extension
Plugin to extend features of Business Era Theme. This plugin registers custom post types, widgets and custom fields for the Business Era theme.
Bonzer Custom Fields Creator Developer Profile
2 plugins · 10 total installs
How We Detect Bonzer Custom Fields Creator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bonzer-custom-fields/assets/css/admin.css/wp-content/plugins/bonzer-custom-fields/assets/css/fontello-arrows.css/wp-content/plugins/bonzer-custom-fields/assets/images/icon.png/wp-content/plugins/bonzer-custom-fields/assets/images/logo_bc_1.png/wp-content/plugins/bonzer-custom-fields/assets/js/bundle.js/wp-content/plugins/bonzer-custom-fields/assets/js/bundle.prod.jsbonzer-custom-fields/assets/css/admin.css?ver=bonzer-custom-fields/assets/css/fontello-arrows.css?ver=bonzer-custom-fields/assets/js/bundle.js?ver=bonzer-custom-fields/assets/js/bundle.prod.js?ver=HTML / DOM Fingerprints
bonzer-custom-fields-creator-headerbonzer-custom-fields-creatorvectorrolealtBCF_ADMIN_AJAX_URLBCF__IS_DEVBCF__CONFIG__HASH/wp-json/bcf/v1/post_types/wp-json/bcf/v1/taxonomies/wp-json/bcf/v1/save_config/wp-json/bcf/v1/load_config/wp-json/bcf/v1/admin_menu_pages