
Custom Fields Notifications Security & Risk Analysis
wordpress.org/plugins/custom-fields-notificationsA tiny plugin which allows to use wordpress custom fileds in notification boxes.
Is Custom Fields Notifications Safe to Use in 2026?
Generally Safe
Score 85/100Custom Fields Notifications has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "custom-fields-notifications" plugin v1.0.1 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices in its handling of SQL queries, exclusively using prepared statements, and has no recorded vulnerabilities or CVEs, suggesting a history of stable and likely secure code. It also lacks external HTTP requests and file operations, reducing common attack vectors.
However, significant concerns arise from the static analysis. The absence of any nonce checks and capability checks, combined with the fact that 0% of its outputs are properly escaped, presents a notable risk. While the attack surface is currently small and appears to have no unauthenticated entry points, the lack of essential security mechanisms like nonces and output escaping makes the existing entry points susceptible to vulnerabilities if any untrusted data is processed or displayed. The taint analysis showing zero flows is positive but might be incomplete if the analysis scope was limited.
Overall, the plugin's lack of documented vulnerabilities is a strength, but the identified weaknesses in output escaping and the complete absence of nonce and capability checks on its single shortcode entry point are critical oversights. These issues could be exploited to introduce cross-site scripting (XSS) vulnerabilities or potentially lead to unauthorized actions if the shortcode interacts with sensitive data or functionality without proper checks. Users should be cautious, and developers should address these immediate security gaps.
Key Concerns
- 0% properly escaped output
- 0 Nonce checks
- 0 Capability checks
Custom Fields Notifications Security Vulnerabilities
Custom Fields Notifications Code Analysis
Output Escaping
Custom Fields Notifications Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Custom Fields Notifications Maintenance & Trust
Maintenance Signals
Community Trust
Custom Fields Notifications Alternatives
Disable Admin Notices – Hide Dashboard Notifications
disable-admin-notices
Disable admin notices and hide dashboard notifications from plugins, themes and core. Hide all notices, selected ones, or show them in a single line.
OneSignal – Web Push Notifications
onesignal-free-web-push-notifications
Increase engagement and drive more repeat traffic to your WordPress site with push notifications. Now a WordPress VIP Gold Partner.
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress
email-subscribers
Add subscription forms on the website and send newsletters & automatically send post notification about new blog posts once it gets published.
ActiveCampaign Postmark for WordPress
postmark-approved-wordpress-plugin
The officially-supported ActiveCampaign Postmark plugin for Wordpress.
WP Telegram (Auto Post and Notifications)
wptelegram
Integrate your WordPress site perfectly with Telegram with full control.
Custom Fields Notifications Developer Profile
4 plugins · 70K total installs
How We Detect Custom Fields Notifications
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-fields-notifications/assets/css/style.css/wp-content/plugins/custom-fields-notifications/assets/css/rtl-style.css/wp-content/plugins/custom-fields-notifications/assets/js/scripts.jsHTML / DOM Fingerprints
notification_containernotificationhideitboot_name="cfn_auto_display"name="cfn_hide_effect"name="cfn_theme"name="custom_fields_notifications"<div class="notification_container" style="margin-top:20px;">