
Convert custom fields to custom taxonomies Security & Risk Analysis
wordpress.org/plugins/custom-fields-to-taxonomiesThe two major systems for adding data to posts in WordPress are custom taxonomies and custom fields. This plugin is useful to convert custom fields in …
Is Convert custom fields to custom taxonomies Safe to Use in 2026?
Generally Safe
Score 100/100Convert custom fields to custom taxonomies has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The custom-fields-to-taxonomies plugin v1.0.3 exhibits significant security concerns primarily due to its unprotected attack surface. All 8 AJAX handlers lack authentication checks, presenting a direct pathway for unauthenticated users to interact with sensitive backend functionalities. While the code shows good practices in output escaping and SQL query preparation, the absence of nonce checks and capability checks on these AJAX handlers is a critical oversight. The taint analysis revealing 4 high-severity flows with unsanitized paths further amplifies this risk, suggesting that user-supplied data can be processed in ways that could lead to vulnerabilities. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator of past secure development. However, this history does not mitigate the immediate risks identified in the static analysis of the current version. In conclusion, while the plugin demonstrates some secure coding habits, the widespread lack of authentication and authorization on its AJAX endpoints, coupled with identified high-severity taint flows, creates a substantial security risk that requires immediate attention.
Key Concerns
- 8 AJAX handlers without auth checks
- 4 high severity taint flows
- 0 nonce checks
- 0 capability checks
Convert custom fields to custom taxonomies Security Vulnerabilities
Convert custom fields to custom taxonomies Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Convert custom fields to custom taxonomies Attack Surface
AJAX Handlers 8
WordPress Hooks 3
Maintenance & Trust
Convert custom fields to custom taxonomies Maintenance & Trust
Maintenance Signals
Community Trust
Convert custom fields to custom taxonomies Alternatives
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
Pods – Custom Content Types and Fields
pods
Pods is a framework for creating, managing, and deploying customized content types and fields for any project.
CubeWP Framework
cubewp-framework
CubeWP is an end-to-end dynamic content framework for WordPress to help you shrink time and cut cost of development up to 90%.
Custom post types, Custom Fields & more
custom-post-types
Custom Post Types, Custom Fields, Custom Taxonomies, Custom Templates, Custom Admin Pages, Custom Admin Notices. Directly from the WP dashboard.
Big Boom Directory
big-boom-directory
Directory management system based on Custom Post Types, Taxonomies, and Fields
Convert custom fields to custom taxonomies Developer Profile
2 plugins · 20 total installs
How We Detect Convert custom fields to custom taxonomies
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-fields-to-taxonomies/css/ctf_tax.css/wp-content/plugins/custom-fields-to-taxonomies/js/ctf_tax.jscustom-fields-to-taxonomies/css/ctf_tax.css?ver=custom-fields-to-taxonomies/js/ctf_tax.js?ver=HTML / DOM Fingerprints
wrap_ctf_to_taxmeta_key_countnotedtable_historyctf_continue_convertdata-keydata-taxctf