
Custom Field Taxonomies Security & Risk Analysis
wordpress.org/plugins/custom-field-taxonomiesConvert custom fields to tags, categories or taxonomy terms
Is Custom Field Taxonomies Safe to Use in 2026?
Generally Safe
Score 85/100Custom Field Taxonomies has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'custom-field-taxonomies' v2.0.3 plugin exhibits a mixed security posture. On one hand, it has a remarkably small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events directly exposed. This is a significant strength, limiting potential entry points for attackers. Furthermore, the absence of known CVEs in its history suggests a generally stable and well-maintained codebase.
However, the static analysis reveals several areas of concern. A significant portion of SQL queries (56%) are not using prepared statements, which could lead to SQL injection vulnerabilities if user input is not meticulously sanitized before being incorporated into these queries. Compounding this, the taint analysis shows a high number of flows with unsanitized paths, including five high-severity flows. This, combined with a very low rate of proper output escaping (15%), indicates a substantial risk of cross-site scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed.
While the plugin has no known historical vulnerabilities, the current static analysis findings present a notable risk. The lack of robust input sanitization and output escaping, particularly evident in the taint analysis, outweighs the minimal attack surface and clean vulnerability history. A cautious approach is recommended until these code-level risks are addressed.
Key Concerns
- High severity unsanitized taint flows
- SQL queries not using prepared statements
- Low rate of proper output escaping
- Unsanitized paths in taint analysis
Custom Field Taxonomies Security Vulnerabilities
Custom Field Taxonomies Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Custom Field Taxonomies Attack Surface
WordPress Hooks 12
Maintenance & Trust
Custom Field Taxonomies Maintenance & Trust
Maintenance Signals
Community Trust
Custom Field Taxonomies Alternatives
JSM Show Post Metadata
jsm-show-post-meta
Show post metadata (aka custom fields) in a metabox when editing posts / pages - a great tool for debugging issues with post metadata.
Taxonomy Metadata
taxonomy-metadata
Infrastructure plugin which implements metadata functionality for taxonomy terms, including for tags and categories.
JSM Show User Metadata
jsm-show-user-meta
Show user metadata in a metabox when editing users - a great tool for debugging issues with user metadata.
WP Term Images
wp-term-images
Images for categories, tags, and other taxonomy terms
JSM Show Term Metadata
jsm-show-term-meta
Show term metadata in a metabox when editing terms - a great tool for debugging issues with term metadata.
Custom Field Taxonomies Developer Profile
20 plugins · 28K total installs
How We Detect Custom Field Taxonomies
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-field-taxonomies/css/custom-field-taxonomies.css/wp-content/plugins/custom-field-taxonomies/js/custom-field-taxonomies.js/wp-content/plugins/custom-field-taxonomies/js/custom-field-taxonomies.jscustom-field-taxonomies/css/custom-field-taxonomies.css?ver=custom-field-taxonomies/js/custom-field-taxonomies.js?ver=HTML / DOM Fingerprints
cft-metabox<!-- Custom Field Taxonomies Admin Notices --><!-- Custom Field Taxonomies -->data-field-keydata-taxonomycft_ajax_object