CMB2 Taxonomy Security & Risk Analysis

wordpress.org/plugins/cmb2-taxonomy

CMB2 Taxonomy will create metaboxes and forms with custom fields for your taxonomies using the CMB2 API (and yes, it will blow your mind too).

200 active installs v1.0.2 PHP + WP 3.8.0+ Updated Dec 21, 2015
fieldsformsmetaboxesoptionssettings
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CMB2 Taxonomy Safe to Use in 2026?

Generally Safe

Score 85/100

CMB2 Taxonomy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The cmb2-taxonomy v1.0.2 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, and external HTTP requests is commendable. Furthermore, 100% of identified output is properly escaped, and the plugin demonstrates good practices with nonce and capability checks in place. The use of prepared statements for SQL queries is also a positive sign, although the total number of SQL queries is relatively low.

Taint analysis revealed no flows with unsanitized paths, and the vulnerability history is clean, with no known CVEs. This indicates a well-maintained and secure codebase for this version.

Overall, the plugin appears robust and secure, adhering to many best practices. The minimal attack surface and lack of identified critical security flaws are strong indicators of a safe plugin. The absence of any recorded vulnerabilities in its history further reinforces this assessment. The strengths lie in its secure coding practices and lack of exploitable entry points.

Vulnerabilities
None known

CMB2 Taxonomy Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

CMB2 Taxonomy Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
2 prepared
Unescaped Output
0
0 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

67% prepared3 total queries
Attack Surface

CMB2 Taxonomy Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filtercmb2-taxonomy_meta_boxesexample-functions.php:20
actioninitincludes\CMB2_Taxonomy.php:17
Maintenance & Trust

CMB2 Taxonomy Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedDec 21, 2015
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings1
Active installs200
Developer Profile

CMB2 Taxonomy Developer Profile

jcchavezs

2 plugins · 220 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CMB2 Taxonomy

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cmb2-taxonomy/assets/css/style.css/wp-content/plugins/cmb2-taxonomy/assets/js/main.js
Script Paths
/wp-content/plugins/cmb2-taxonomy/assets/js/main.js
Version Parameters
cmb2-taxonomy/assets/css/style.css?ver=cmb2-taxonomy/assets/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
cmb2-taxonomy
HTML Comments
-- include and setup custom metaboxes and fields. (make sure you copy this file to outside the CMB Taxonomy directory) ---- Get the bootstrap! If using the plugin from wordpress.org, REMOVE THIS! --
Data Attributes
data-id="cmb2_taxonomy"data-taxonomy="cmb2_taxonomy"
JS Globals
window.cmb2_taxonomy_settings
FAQ

Frequently Asked Questions about CMB2 Taxonomy