
CMB2 Admin Extension Security & Risk Analysis
wordpress.org/plugins/cmb2-admin-extensionCreate and manage CMB2 meta boxes from the WordPress admin without writing code.
Is CMB2 Admin Extension Safe to Use in 2026?
Generally Safe
Score 100/100CMB2 Admin Extension has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The cmb2-admin-extension v1.0.7 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength. Furthermore, the code demonstrates good practices by not using dangerous functions, performing all SQL queries with prepared statements, and avoiding file operations and external HTTP requests. The presence of a capability check, albeit a single one, is also positive.
However, the analysis does highlight a couple of minor areas for improvement. While the majority of outputs are properly escaped, there is a small percentage that are not, which could present a low-level risk if the unescaped data is user-controlled and displayed in sensitive contexts. The complete lack of taint analysis results and the absence of nonce checks on any potential entry points (though there are none identified) suggest that while the current attack surface is minimal, the plugin has not been thoroughly tested for potential cross-site scripting (XSS) or other injection vulnerabilities that might arise if new functionalities were added without proper sanitization and authorization checks.
The vulnerability history being completely clear of any recorded CVEs is a very positive indicator, suggesting a well-maintained and secure development history. This, combined with the current static analysis findings, leads to an overall assessment of good security. The plugin appears to be developed with security in mind, prioritizing secure coding practices for its current feature set. The main takeaway is that while currently very secure due to a limited attack surface, future development should incorporate more comprehensive sanitization and authorization checks, especially if the plugin's functionality expands.
Key Concerns
- Unescaped output detected
- Lack of nonce checks on potential entry points
CMB2 Admin Extension Security Vulnerabilities
CMB2 Admin Extension Code Analysis
Output Escaping
CMB2 Admin Extension Attack Surface
WordPress Hooks 16
Maintenance & Trust
CMB2 Admin Extension Maintenance & Trust
Maintenance Signals
Community Trust
CMB2 Admin Extension Alternatives
CMB2
cmb2
CMB2 is a metabox, custom fields, and forms library for WordPress that will blow your mind.
CMB2 Taxonomy
cmb2-taxonomy
CMB2 Taxonomy will create metaboxes and forms with custom fields for your taxonomies using the CMB2 API (and yes, it will blow your mind too).
One Click Demo Import
one-click-demo-import
Import your demo content, widgets and theme settings with one click. Theme authors! Enable simple theme demo import for your users.
Conditional Fields for Contact Form 7
cf7-conditional-fields
Adds conditional logic to Contact Form 7.
OptionTree
option-tree
Theme Options UI Builder for WordPress. A simple way to create & save Theme Options and Meta Boxes for free or premium themes.
CMB2 Admin Extension Developer Profile
3 plugins · 500 total installs
How We Detect CMB2 Admin Extension
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cmb2-admin-extension/assets/css/cmb2-admin-extension.css/wp-content/plugins/cmb2-admin-extension/assets/js/cmb2-admin-extension.js/wp-content/plugins/cmb2-admin-extension/assets/js/cmb2-admin-extension.jscmb2-admin-extension/assets/css/cmb2-admin-extension.css?ver=cmb2-admin-extension/assets/js/cmb2-admin-extension.js?ver=HTML / DOM Fingerprints
cmb2-admin-extensiondata-cmb2ae-user-idcmb2_admin_extension_params