Bonzer Custom Fields Creator Security & Risk Analysis

wordpress.org/plugins/bonzer-custom-fields

Create wide array of input fields at various location in the admin panel.

10 active installs v1.1.1 PHP 5.4+ WP 4.9.23+ Updated Jan 6, 2026
custom-fieldsfieldsmetaboxprofile-fieldstaxonomy-fields
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Bonzer Custom Fields Creator Safe to Use in 2026?

Generally Safe

Score 100/100

Bonzer Custom Fields Creator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "bonzer-custom-fields" v1.1.1 plugin exhibits a mixed security posture. On one hand, it demonstrates good practices in its SQL query handling, with 100% of queries using prepared statements, and it has no recorded vulnerability history, suggesting a potentially stable and well-maintained codebase. However, significant concerns arise from its attack surface and code analysis.

The plugin exposes a substantial attack surface through 6 AJAX handlers, with an alarming 5 of them lacking authentication checks. This means potentially sensitive operations could be triggered by any visitor to the site. Furthermore, the taint analysis reveals 4 flows with unsanitized paths, which, while not currently classified as critical or high severity, indicate potential pathways for malicious input to reach sensitive functions or the filesystem. The presence of `shell_exec` is a critical function that, when combined with unsanitized inputs, can lead to remote code execution. The output escaping is also problematic, with nearly half of the outputs not being properly escaped, increasing the risk of cross-site scripting (XSS) vulnerabilities.

While the lack of known CVEs is positive, it should not be relied upon as the sole indicator of security. The significant number of unprotected entry points and the concerning taint analysis results present immediate risks that need to be addressed. The plugin has strengths in its SQL handling and lack of history, but these are overshadowed by the present, identifiable vulnerabilities in its attack surface and code execution/output handling.

Key Concerns

  • AJAX handlers without authentication
  • Unsanitized paths in taint analysis
  • Dangerous function: shell_exec
  • Low output escaping percentage
  • Missing capability checks
  • Missing nonce checks on AJAX
Vulnerabilities
None known

Bonzer Custom Fields Creator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Bonzer Custom Fields Creator Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
28
23 escaped
Nonce Checks
2
Capability Checks
0
File Operations
6
External Requests
0
Bundled Libraries
1

Dangerous Functions Found

shell_exec$output = shell_exec('php -l '.$file);inc\Options_Factory.php:594

Bundled Libraries

jQuery

Output Escaping

45% escaped51 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

6 flows4 with unsanitized paths
save_config (inc\Bonzer_Custom_Fields.php:384)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
5 unprotected

Bonzer Custom Fields Creator Attack Surface

Entry Points6
Unprotected5

AJAX Handlers 6

authwp_ajax_bcf_load_post_typesinc\Bonzer_Custom_Fields.php:88
authwp_ajax_bcf_load_taxonomiesinc\Bonzer_Custom_Fields.php:89
authwp_ajax_bcf_save_configinc\Bonzer_Custom_Fields.php:90
authwp_ajax_bcf_load_configinc\Bonzer_Custom_Fields.php:91
authwp_ajax_bcf_load_admin_menu_pagesinc\Bonzer_Custom_Fields.php:92
authwp_ajax_load_inputs_previewinc\Previewer.php:104
WordPress Hooks 15
actionadmin_enqueue_scriptsinc\Bonzer_Custom_Fields.php:85
actionadmin_menuinc\Bonzer_Custom_Fields.php:86
actionadmin_initinc\Bonzer_Custom_Fields.php:178
actionadd_meta_boxesinc\builders\Custom_Fields_Builder.php:103
actionsave_postinc\builders\Custom_Fields_Builder.php:104
actionwp_dashboard_setupinc\builders\Dashboard_Fields_Builder.php:55
actionshow_user_profileinc\builders\Profile_Fields_Builder.php:48
actionpersonal_options_updateinc\builders\Profile_Fields_Builder.php:49
actionadmin_initinc\builders\Settings_Fields_Builder.php:47
actionedit_terminc\builders\Taxonomy_Fields_Builder.php:55
actioncreated_terminc\builders\Taxonomy_Fields_Builder.php:56
actionsave_postinc\contracts\Custom_Fields_Abstract.php:25
actioninitinc\Options_Factory.php:102
actionadmin_headinc\Options_Factory.php:191
actionadmin_footerinc\Options_Factory.php:203
Maintenance & Trust

Bonzer Custom Fields Creator Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 6, 2026
PHP min version5.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Bonzer Custom Fields Creator Developer Profile

Paras Ralhan

2 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bonzer Custom Fields Creator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bonzer-custom-fields/assets/css/admin.css/wp-content/plugins/bonzer-custom-fields/assets/css/fontello-arrows.css/wp-content/plugins/bonzer-custom-fields/assets/images/icon.png/wp-content/plugins/bonzer-custom-fields/assets/images/logo_bc_1.png/wp-content/plugins/bonzer-custom-fields/assets/js/bundle.js/wp-content/plugins/bonzer-custom-fields/assets/js/bundle.prod.js
Version Parameters
bonzer-custom-fields/assets/css/admin.css?ver=bonzer-custom-fields/assets/css/fontello-arrows.css?ver=bonzer-custom-fields/assets/js/bundle.js?ver=bonzer-custom-fields/assets/js/bundle.prod.js?ver=

HTML / DOM Fingerprints

CSS Classes
bonzer-custom-fields-creator-headerbonzer-custom-fields-creatorvector
Data Attributes
rolealt
JS Globals
BCF_ADMIN_AJAX_URLBCF__IS_DEVBCF__CONFIG__HASH
REST Endpoints
/wp-json/bcf/v1/post_types/wp-json/bcf/v1/taxonomies/wp-json/bcf/v1/save_config/wp-json/bcf/v1/load_config/wp-json/bcf/v1/admin_menu_pages
FAQ

Frequently Asked Questions about Bonzer Custom Fields Creator