
Custom Fields to Metaboxes Security & Risk Analysis
wordpress.org/plugins/custom-fields-to-metaboxesMigrate custom fields to metabox fields.
Is Custom Fields to Metaboxes Safe to Use in 2026?
Generally Safe
Score 85/100Custom Fields to Metaboxes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'custom-fields-to-metaboxes' plugin v0.1.1 exhibits a concerning security posture primarily due to its unprotected entry points. While the plugin demonstrates good practices by using prepared statements for SQL queries and having no known vulnerabilities or dangerous functions, the presence of three AJAX handlers without authentication checks presents a significant risk. This means that any user, including unauthenticated ones, could potentially trigger these AJAX actions, leading to unintended consequences or exploitation if the handler logic is flawed. The lack of capability checks further exacerbates this issue, as it offers no granular control over who can perform these actions. The plugin's static analysis reveals a complete absence of output escaping, which is a critical oversight. This means that any data processed or displayed through these AJAX handlers could be vulnerable to Cross-Site Scripting (XSS) attacks. The absence of taint analysis results and vulnerability history, while seemingly positive, does not negate the identified risks. In conclusion, the plugin has strengths in its SQL handling and lack of known vulnerabilities, but the unprotected AJAX endpoints coupled with absent output escaping create a substantial risk profile that requires immediate attention.
Key Concerns
- Unprotected AJAX handlers
- No output escaping
- No capability checks on AJAX
Custom Fields to Metaboxes Security Vulnerabilities
Custom Fields to Metaboxes Code Analysis
Output Escaping
Custom Fields to Metaboxes Attack Surface
AJAX Handlers 3
WordPress Hooks 3
Maintenance & Trust
Custom Fields to Metaboxes Maintenance & Trust
Maintenance Signals
Community Trust
Custom Fields to Metaboxes Alternatives
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
MB ACF Migration
mb-acf-migration
Migrate custom fields from Advanced Custom Fields to Meta Box.
CubeWP Framework
cubewp-framework
CubeWP is an end-to-end dynamic content framework for WordPress to help you shrink time and cut cost of development up to 90%.
MB Elementor Integration
mb-elementor-integrator
Integrates Meta Box's custom fields with Elementor page builder via dynamic tags.
Custom Fields for Gutenberg
custom-fields-gutenberg
Restores the Custom Field meta box for the Gutenberg Block Editor.
Custom Fields to Metaboxes Developer Profile
5 plugins · 50 total installs
How We Detect Custom Fields to Metaboxes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-fields-to-metaboxes/js/admin.js/wp-content/plugins/custom-fields-to-metaboxes/css/admin.css/wp-content/plugins/custom-fields-to-metaboxes/js/admin.jscustom-fields-to-metaboxes/js/admin.js?ver=custom-fields-to-metaboxes/css/admin.css?ver=HTML / DOM Fingerprints
cftmb-admin-pagecftmb-stepscftmb-db-backup-warningcftmb-admin-noticesdata-metabox_iddata-post_typeid="post_type"id="metabox_id"name="custom_fields[]"name="metabox_fields[]"options