
Custom Fields for Gutenberg Security & Risk Analysis
wordpress.org/plugins/custom-fields-gutenbergRestores the Custom Field meta box for the Gutenberg Block Editor.
Is Custom Fields for Gutenberg Safe to Use in 2026?
Generally Safe
Score 100/100Custom Fields for Gutenberg has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'custom-fields-gutenberg' v2.4.5 exhibits a generally strong security posture based on the provided static analysis. The absence of any reported CVEs, coupled with the fact that all SQL queries utilize prepared statements, indicates good development practices regarding data integrity and common web vulnerabilities. The presence of nonce and capability checks on a reasonable number of code paths further bolsters its security, suggesting an awareness of potential unauthorized access. The complete lack of dangerous functions, file operations, and external HTTP requests is also a positive sign, reducing the plugin's overall attack surface and potential for exploitation.
However, the static analysis reveals a concerning area: output escaping. With 63% of outputs properly escaped, this leaves a significant portion (37%) potentially vulnerable to Cross-Site Scripting (XSS) attacks. While there are no reported taint flows or critical/high severity vulnerabilities identified, this unescaped output represents a tangible risk that could be leveraged by attackers if a malicious input is processed and rendered without proper sanitization. The plugin's vulnerability history is clean, which is excellent, but this does not negate the identified weakness in output handling. In conclusion, while the plugin demonstrates strong foundational security, the unescaped output is a notable weakness that warrants attention and remediation to achieve a truly secure state.
Key Concerns
- Output escaping is not fully implemented
Custom Fields for Gutenberg Security Vulnerabilities
Custom Fields for Gutenberg Code Analysis
SQL Query Safety
Output Escaping
Custom Fields for Gutenberg Attack Surface
WordPress Hooks 17
Maintenance & Trust
Custom Fields for Gutenberg Maintenance & Trust
Maintenance Signals
Community Trust
Custom Fields for Gutenberg Alternatives
Stepfox Looks
stepfox-looks
Enhances the block editor with responsive controls, custom blocks, and extensions for modern magazine and news sites.
Voxycure Framework
voxycure-framework
Create custom fields, blocks, and post types with no limitations. A flexible, free solution for building with custom data in WordPress.
Spectra Gutenberg Blocks – Website Builder for the Block Editor
ultimate-addons-for-gutenberg
Power-up Gutenberg with advanced blocks for faster website creation. Build your WordPress website effortlessly using powerful building blocks!
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
kadence-blocks
20+ AI-powered Gutenberg Blocks with endless options, enabling top-notch efficiency for high-performance dynamic website creation.
Extendify
extendify
The best WordPress templates, pattern, and layout library with 1,000+ designs built for the Gutenberg block editor.
Custom Fields for Gutenberg Developer Profile
30 plugins · 1.2M total installs
How We Detect Custom Fields for Gutenberg
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-fields-gutenberg/css/font-awesome.min.css/wp-content/plugins/custom-fields-gutenberg/css/plugin-settings.css/wp-content/plugins/custom-fields-gutenberg/js/plugin-settings.js/wp-content/plugins/custom-fields-gutenberg/js/gutenberg-custom-fields.js/wp-content/plugins/custom-fields-gutenberg/js/plugin-settings.jscustom-fields-gutenberg/css/font-awesome.min.css?ver=custom-fields-gutenberg/css/plugin-settings.css?ver=custom-fields-gutenberg/js/gutenberg-custom-fields.js?ver=custom-fields-gutenberg/js/plugin-settings.js?ver=HTML / DOM Fingerprints
g7g-cfg-admin-noticeg7g-cfg-settingsdata-post-typedata-field-nameg7g_cfg_vars