
Custom Field Builder – WordPress custom fields plugin Security & Risk Analysis
wordpress.org/plugins/custom-field-builderCustom Field Builder is a powerful and lightweight developer plugin to create custom meta boxes and custom fields for WordPress.
Is Custom Field Builder – WordPress custom fields plugin Safe to Use in 2026?
Generally Safe
Score 85/100Custom Field Builder – WordPress custom fields plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "custom-field-builder" plugin version 1.2.4 exhibits a concerning security posture primarily due to a significant lack of input sanitization and authentication checks. The static analysis reveals one AJAX handler that does not implement any authentication checks, making it a direct entry point for potential attackers. Furthermore, all SQL queries are executed without prepared statements, indicating a high risk of SQL injection vulnerabilities. The taint analysis highlights two flows with unsanitized paths, both classified as high severity. This suggests that data entering the plugin is not being properly validated before being used in sensitive operations. While there is no recorded vulnerability history, this should not be interpreted as a sign of strong security, but rather a potential lack of past scrutiny or reporting. The limited attack surface is a minor positive, but it is overshadowed by the critical weaknesses identified in the code's handling of user input and database interactions. Without addressing the unauthenticated AJAX endpoint and the raw SQL queries, the plugin remains highly vulnerable.
Key Concerns
- Unauthenticated AJAX handler
- SQL queries without prepared statements
- High severity unsanitized taint flows
- Low percentage of properly escaped output
- No nonce checks on entry points
Custom Field Builder – WordPress custom fields plugin Security Vulnerabilities
Custom Field Builder – WordPress custom fields plugin Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Custom Field Builder – WordPress custom fields plugin Attack Surface
AJAX Handlers 1
WordPress Hooks 6
Maintenance & Trust
Custom Field Builder – WordPress custom fields plugin Maintenance & Trust
Maintenance Signals
Community Trust
Custom Field Builder – WordPress custom fields plugin Alternatives
Codeideal Open Fields
codeideal-open-fields
A free, modern custom fields plugin for WordPress. Build field groups with a visual editor — no code required.
Advanced Custom Fields (ACF®)
advanced-custom-fields
ACF helps customize WordPress with powerful, professional and intuitive fields. Proudly powering over 2 million sites, WordPress developers love ACF.
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
Checkout Field Editor (Checkout Manager) for WooCommerce
woo-checkout-field-editor-pro
Checkout Field Editor (Checkout Manager) for WooCommerce – The best WooCommerce checkout manager plugin to manage WooCommerce checkout fields.
ACF Content Analysis for Yoast SEO
acf-content-analysis-for-yoast-seo
WordPress plugin that adds the content of all ACF fields to the Yoast SEO score analysis.
Custom Field Builder – WordPress custom fields plugin Developer Profile
5 plugins · 7K total installs
How We Detect Custom Field Builder – WordPress custom fields plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-field-builder/assets/css/style.min.css/wp-content/plugins/custom-field-builder/assets/js/core.min.js/wp-content/plugins/custom-field-builder/assets/js/core.min.jscf-builder-csscf-builder-jsHTML / DOM Fingerprints
cfb-inputcfb-editorcfb-media-uploadcfb-post-relationship-itemcfb-checkbox-group-inputdata-cfb-field-typedata-cfb-field-iddata-cfb-editor-idCFBuilder/wp-json/cfb/v1/relationship/find