
Custom Fields Shortcodes Security & Risk Analysis
wordpress.org/plugins/custom-fields-shortcodesLets you insert custom fields in the visual editor without coding in PHP.
Is Custom Fields Shortcodes Safe to Use in 2026?
Generally Safe
Score 85/100Custom Fields Shortcodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The custom-fields-shortcodes plugin v0.9 presents a mixed security posture. On the positive side, it has no known vulnerabilities in its history, no external HTTP requests, no file operations, and all SQL queries utilize prepared statements. The attack surface is also minimal, consisting of a single shortcode with no apparent auth checks or nonce protections, and no AJAX or REST API endpoints are exposed without authorization. This suggests a level of care in preventing common web vulnerabilities.
However, significant concerns arise from the static analysis. The presence of the `unserialize` function is a critical red flag, as unsanitized serialized data can lead to remote code execution vulnerabilities. Furthermore, only 20% of output escaping is properly implemented, leaving potential for cross-site scripting (XSS) vulnerabilities. The lack of nonce checks on the shortcode, which is the sole entry point, is also a notable weakness, potentially allowing for cross-site request forgery (CSRF) attacks if the shortcode performs any sensitive actions.
While the plugin has no historical vulnerabilities, this does not guarantee future safety, especially given the identified code-level risks. The absence of known CVEs might indicate a lack of widespread testing or a relatively new plugin. The plugin's strengths lie in its controlled SQL usage and lack of external dependencies. However, the combination of `unserialize`, insufficient output escaping, and missing nonce checks on its only entry point creates tangible security risks that require immediate attention.
Key Concerns
- Dangerous function: unserialize used
- Output escaping only 20% proper
- Shortcode lacks nonce check
- Shortcode lacks capability check
Custom Fields Shortcodes Security Vulnerabilities
Custom Fields Shortcodes Code Analysis
Dangerous Functions Found
Output Escaping
Custom Fields Shortcodes Attack Surface
Shortcodes 1
WordPress Hooks 13
Maintenance & Trust
Custom Fields Shortcodes Maintenance & Trust
Maintenance Signals
Community Trust
Custom Fields Shortcodes Alternatives
Checkout Field Editor (Checkout Manager) for WooCommerce
woo-checkout-field-editor-pro
Checkout Field Editor (Checkout Manager) for WooCommerce – The best WooCommerce checkout manager plugin to manage WooCommerce checkout fields.
Custom Shortcodes
custom-shortcodes
Manage custom fields using the insert shortcodes or HTML comment in text of post.
Digital Goods (Checkout Field Editor) for WooCommerce Checkout
woo-checkout-for-digital-goods
This plugin will remove billing address fields for downloadable and virtual products.
Custom WooCommerce Checkout Fields Editor
add-fields-to-checkout-page-woocommerce
Custom WooCommerce Checkout Fields Editor
Custom Field For WP Job Manager
custom-field-for-wp-job-manager
The ultimate field editor for WP Job Manager. Easily add, edit, and manage custom job and company fields without any coding.
Custom Fields Shortcodes Developer Profile
9 plugins · 108K total installs
How We Detect Custom Fields Shortcodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-fields-shortcodes/style.csscustom-fields-shortcodes/style.css?ver=HTML / DOM Fingerprints
wptacf-custom-fields-shortcodes[cf-shortcode field=[cf-shortcode plugin=[cf-shortcode field= "[cf-shortcode plugin= "