CFS Custom Category Fields Security & Risk Analysis

wordpress.org/plugins/cfs-custom-category-fields

A Custom Field Suite Addon that provides custom meta data for categories and custom taxonomies.

200 active installs v1.3.1 PHP + WP 3.6+ Updated Nov 7, 2015
category-custom-fieldscategory-meta-datacustom-field-suite-addon
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CFS Custom Category Fields Safe to Use in 2026?

Generally Safe

Score 85/100

CFS Custom Category Fields has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The cfs-custom-category-fields plugin version 1.3.1 exhibits a generally positive security posture based on the static analysis and vulnerability history. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events indicates a minimal attack surface, which is a significant strength. Furthermore, the plugin demonstrates good practices in its SQL query handling by exclusively using prepared statements and includes capability checks, suggesting an awareness of secure coding principles. The lack of any recorded vulnerabilities, including CVEs, reinforces this perception of a relatively secure plugin.

However, a notable concern arises from the output escaping results, where 0% of the total outputs are properly escaped. This presents a risk of cross-site scripting (XSS) vulnerabilities if any of the plugin's output contains user-supplied or dynamic data that is not adequately sanitized before being rendered in the browser. While taint analysis shows no critical or high severity flows, the lack of escaping is a direct entry point for potential XSS attacks. The absence of nonce checks, while not immediately a critical issue given the limited attack surface, could become a weakness if new entry points are introduced in future versions without proper security controls.

In conclusion, cfs-custom-category-fields 1.3.1 is strong in its limited attack surface and SQL security. The primary weakness lies in the unescaped output, which warrants attention. The clean vulnerability history is encouraging, but the identified output escaping flaw is a tangible risk that should be addressed to ensure continued security.

Key Concerns

  • 0% of output properly escaped
Vulnerabilities
None known

CFS Custom Category Fields Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

CFS Custom Category Fields Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

CFS Custom Category Fields Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 24
filtercfs_matching_groupscfs-taxonomy.php:65
actionadmin_noticescfs-taxonomy.php:214
actionnetwork_admin_noticescfs-taxonomy.php:215
filtercfs_matching_groupscfs-taxonomy.php:256
filtercfs_matching_groupscfs-taxonomy.php:323
actioninitcfs-taxonomy.php:364
actionadmin_initcfs-taxonomy.php:365
actioncfs_initcfs-taxonomy.php:366
actionadd_meta_boxescfs-taxonomy.php:367
actionadmin_enqueue_scriptscfs-taxonomy.php:368
actionsave_post_cfscfs-taxonomy.php:369
filtercfs_matching_groupscfs-taxonomy.php:370
filtercfs_matching_groupstrunk\cfs-taxonomy.php:65
actionadmin_noticestrunk\cfs-taxonomy.php:214
actionnetwork_admin_noticestrunk\cfs-taxonomy.php:215
filtercfs_matching_groupstrunk\cfs-taxonomy.php:256
filtercfs_matching_groupstrunk\cfs-taxonomy.php:323
actioninittrunk\cfs-taxonomy.php:364
actionadmin_inittrunk\cfs-taxonomy.php:365
actioncfs_inittrunk\cfs-taxonomy.php:366
actionadd_meta_boxestrunk\cfs-taxonomy.php:367
actionadmin_enqueue_scriptstrunk\cfs-taxonomy.php:368
actionsave_post_cfstrunk\cfs-taxonomy.php:369
filtercfs_matching_groupstrunk\cfs-taxonomy.php:370
Maintenance & Trust

CFS Custom Category Fields Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedNov 7, 2015
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings2
Active installs200
Alternatives

CFS Custom Category Fields Alternatives

No alternatives data available yet.

Developer Profile

CFS Custom Category Fields Developer Profile

GatorDog

2 plugins · 300 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CFS Custom Category Fields

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cfs-custom-category-fields/assets/css/cfs-taxonomy.css/wp-content/plugins/cfs-custom-category-fields/assets/js/cfs-taxonomy.js
Script Paths
/wp-content/plugins/cfs-custom-category-fields/assets/js/cfs-taxonomy.js
Version Parameters
cfs-custom-category-fields/assets/css/cfs-taxonomy.css?ver=cfs-custom-category-fields/assets/js/cfs-taxonomy.js?ver=

HTML / DOM Fingerprints

CSS Classes
cfs_input
Data Attributes
data-cfs-field-id
JS Globals
cfsTaxonomy
FAQ

Frequently Asked Questions about CFS Custom Category Fields