Custom Field Taxonomies Security & Risk Analysis

wordpress.org/plugins/custom-field-taxonomies

Convert custom fields to tags, categories or taxonomy terms

60 active installs v2.0.3 PHP + WP 3.2+ Updated Sep 26, 2012
custom-fieldsmetametadatataxonomy
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Custom Field Taxonomies Safe to Use in 2026?

Generally Safe

Score 85/100

Custom Field Taxonomies has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The 'custom-field-taxonomies' v2.0.3 plugin exhibits a mixed security posture. On one hand, it has a remarkably small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events directly exposed. This is a significant strength, limiting potential entry points for attackers. Furthermore, the absence of known CVEs in its history suggests a generally stable and well-maintained codebase.

However, the static analysis reveals several areas of concern. A significant portion of SQL queries (56%) are not using prepared statements, which could lead to SQL injection vulnerabilities if user input is not meticulously sanitized before being incorporated into these queries. Compounding this, the taint analysis shows a high number of flows with unsanitized paths, including five high-severity flows. This, combined with a very low rate of proper output escaping (15%), indicates a substantial risk of cross-site scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed.

While the plugin has no known historical vulnerabilities, the current static analysis findings present a notable risk. The lack of robust input sanitization and output escaping, particularly evident in the taint analysis, outweighs the minimal attack surface and clean vulnerability history. A cautious approach is recommended until these code-level risks are addressed.

Key Concerns

  • High severity unsanitized taint flows
  • SQL queries not using prepared statements
  • Low rate of proper output escaping
  • Unsanitized paths in taint analysis
Vulnerabilities
None known

Custom Field Taxonomies Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Custom Field Taxonomies Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
4 prepared
Unescaped Output
23
4 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

44% prepared9 total queries

Output Escaping

15% escaped27 total outputs
Data Flows
6 unsanitized

Data Flow Analysis

6 flows6 with unsanitized paths
handler (admin.php:14)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Custom Field Taxonomies Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionadmin_noticesadmin.php:8
actiontool_boxadmin.php:9
action_admin_menuscb\AdminPage.php:49
actionadmin_initscb\AdminPage.php:91
actionadmin_noticesscb\AdminPage.php:93
actionadmin_menuscb\AdminPage.php:96
filtercontextual_helpscb\AdminPage.php:97
actionadmin_footerscb\AdminPage.php:322
filtercron_schedulesscb\Cron.php:57
actionactivate_pluginscb\load.php:32
actionplugins_loadedscb\load.php:38
actionwidgets_initscb\Widget.php:13
Maintenance & Trust

Custom Field Taxonomies Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedSep 26, 2012
PHP min version
Downloads16K

Community Trust

Rating92/100
Number of ratings5
Active installs60
Developer Profile

Custom Field Taxonomies Developer Profile

scribu

20 plugins · 28K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
4851 days
View full developer profile
Detection Fingerprints

How We Detect Custom Field Taxonomies

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/custom-field-taxonomies/css/custom-field-taxonomies.css/wp-content/plugins/custom-field-taxonomies/js/custom-field-taxonomies.js
Script Paths
/wp-content/plugins/custom-field-taxonomies/js/custom-field-taxonomies.js
Version Parameters
custom-field-taxonomies/css/custom-field-taxonomies.css?ver=custom-field-taxonomies/js/custom-field-taxonomies.js?ver=

HTML / DOM Fingerprints

CSS Classes
cft-metabox
HTML Comments
<!-- Custom Field Taxonomies Admin Notices --><!-- Custom Field Taxonomies -->
Data Attributes
data-field-keydata-taxonomy
JS Globals
cft_ajax_object
FAQ

Frequently Asked Questions about Custom Field Taxonomies