Metabox Glue Security & Risk Analysis

wordpress.org/plugins/cubecolour-metabox-glue

Glues the editor metaboxes in place so they cannot be repositioned or minimised.

10 active installs v1.3.0 PHP + WP 4.2+ Updated Jun 23, 2025
adminfixgluemeta-boxmetabox
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Metabox Glue Safe to Use in 2026?

Generally Safe

Score 100/100

Metabox Glue has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The cubecolour-metabox-glue plugin v1.3.0 demonstrates an exceptionally strong security posture based on the provided static analysis and vulnerability history. The complete absence of any identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) significantly minimizes the potential attack surface. Furthermore, the code analysis reveals a diligent adherence to secure coding practices, with no dangerous functions, file operations, or external HTTP requests. All SQL queries are properly prepared, and all output is correctly escaped, mitigating common web vulnerabilities like SQL injection and Cross-Site Scripting (XSS). The lack of any recorded vulnerabilities, past or present, reinforces this positive assessment.

While the plugin exhibits excellent security hygiene, the absolute absence of any nonces or capability checks across all analyzed components is a notable point of concern. Although there are no active entry points to exploit, if any were to be introduced in the future without proper authorization checks, they would be inherently unprotected. This doesn't represent an immediate exploit, but a potential for future vulnerability should the plugin evolve. Overall, cubecolour-metabox-glue v1.3.0 is commendably secure, with its primary weakness being the lack of foundational authorization checks, which, in the absence of an attack surface, is a theoretical rather than practical concern at this time.

Key Concerns

  • Missing capability checks on all entry points
  • Missing nonce checks on all entry points
Vulnerabilities
None known

Metabox Glue Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Metabox Glue Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Metabox Glue Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterplugin_row_metacubecolour-metabox-glue.php:63
actionadmin_enqueue_scriptscubecolour-metabox-glue.php:74
actionadmin_enqueue_scriptscubecolour-metabox-glue.php:112
actionadd_meta_boxescubecolour-metabox-glue.php:115
Maintenance & Trust

Metabox Glue Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 23, 2025
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Metabox Glue Developer Profile

cubecolour

17 plugins · 21K total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Metabox Glue

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cubecolour-metabox-glue/js/metabox-glue.js
Script Paths
/wp-content/plugins/cubecolour-metabox-glue/js/metabox-glue.js
Version Parameters
cubecolour-metabox-glue/js/metabox-glue.js?ver=1.1.1

HTML / DOM Fingerprints

CSS Classes
dashicons-beforedashicons-yes
Data Attributes
title="Unglue Metaboxes"title="Metaboxes are glued"
FAQ

Frequently Asked Questions about Metabox Glue