
Conditional Custom Fields Shortcode Security & Risk Analysis
wordpress.org/plugins/conditional-custom-fields-shortcodeUse custom field values in you pages or posts. With conditional supports which enables basic templating with custom fields.
Is Conditional Custom Fields Shortcode Safe to Use in 2026?
Generally Safe
Score 85/100Conditional Custom Fields Shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "conditional-custom-fields-shortcode" plugin v0.5 exhibits a generally strong security posture due to its adherence to secure coding practices. The absence of raw SQL queries, proper output escaping, and lack of file operations or external HTTP requests are significant strengths. Furthermore, the absence of any known historical vulnerabilities or CVEs suggests a history of stable and secure development. However, the presence of two 'create_function' calls is a notable concern. This function is deprecated and can be a source of potential security risks if not used with extreme caution, as it allows for the creation of functions from strings, which can be susceptible to code injection if the input string is not strictly sanitized. Despite this, the overall low risk is further reinforced by the limited attack surface comprised solely of shortcodes and the lack of any taint analysis findings.
Key Concerns
- Use of deprecated create_function
Conditional Custom Fields Shortcode Security Vulnerabilities
Conditional Custom Fields Shortcode Code Analysis
Dangerous Functions Found
Output Escaping
Conditional Custom Fields Shortcode Attack Surface
Shortcodes 9
WordPress Hooks 2
Maintenance & Trust
Conditional Custom Fields Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
Conditional Custom Fields Shortcode Alternatives
Magic Fields 2 Toolkit
magic-fields-2-toolkit
A toolkit for the Magic Fields 2 plugin for media oriented CMS web design by non programmers.
Supple Forms
supple-forms
Supple Forms - a CMS plugin for WordPress to create custom write panels, and format and insert values into Posts.
Custom Field Template
custom-field-template
The Custom Field Template plugin extends the functionality of custom fields.
Custom Shortcodes
custom-shortcodes
Manage custom fields using the insert shortcodes or HTML comment in text of post.
CubeWP Forms
cubewp-forms
CubeWP Forms is a 100% free drag-and-drop builder for creating contact forms, lead gen forms, appointment request forms, and newsletter signup forms.
Conditional Custom Fields Shortcode Developer Profile
15 plugins · 6K total installs
How We Detect Conditional Custom Fields Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/conditional-custom-fields-shortcode/conditional-custom-fields-functions.phpHTML / DOM Fingerprints
[cf[if-cf-def[if-cf-ndef[if-cf-eq