
Custom Global Variables Security & Risk Analysis
wordpress.org/plugins/custom-global-variablesEasily create custom variables that can be accessed globally in Wordpress and PHP. Retrieval of information is extremely fast, with no database calls.
Is Custom Global Variables Safe to Use in 2026?
Generally Safe
Score 85/100Custom Global Variables has a strong security track record. Known vulnerabilities have been patched promptly.
The 'custom-global-variables' plugin, version 1.1.2, presents a mixed security profile. On the positive side, it demonstrates good practices regarding SQL queries, exclusively using prepared statements, and incorporates nonce and capability checks. The attack surface is minimal, with only one shortcode and no AJAX handlers, REST API routes, or cron events, and crucially, all entry points appear to be protected. Taint analysis shows no critical or high-severity vulnerabilities, suggesting a lack of complex data flow issues in this version.
However, there are significant concerns. A substantial portion (64%) of output escaping is not properly handled, indicating a risk of Cross-Site Scripting (XSS) vulnerabilities. The plugin also performs file operations without explicit indication of sanitization or permission checks, and the history of one medium-severity CVE for XSS in 2021 highlights a past weakness in output neutralization. While the current version has no unpatched CVEs, the historical XSS vulnerability and the high rate of unescaped output are concerning indicators that input validation and output escaping require careful attention to prevent potential security breaches.
Key Concerns
- High percentage of unescaped output
- Past XSS vulnerability (medium severity)
- File operations without clear security checks
Custom Global Variables Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Custom Global Variables <= 1.0.5 - Stored Cross-Site Scripting via 'name'
Custom Global Variables Code Analysis
Output Escaping
Custom Global Variables Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Custom Global Variables Maintenance & Trust
Maintenance Signals
Community Trust
Custom Global Variables Alternatives
Template Dictionary
template-dictionary
A plugin for developers which provides template variables dictionary editable in backend.
One Click Demo Import
one-click-demo-import
Import your demo content, widgets and theme settings with one click. Theme authors! Enable simple theme demo import for your users.
CMB2
cmb2
CMB2 is a metabox, custom fields, and forms library for WordPress that will blow your mind.
OptionTree
option-tree
Theme Options UI Builder for WordPress. A simple way to create & save Theme Options and Meta Boxes for free or premium themes.
Catch Themes Demo Import
catch-themes-demo-import
Catch Themes Demo Import is a simple and easy-to-use demo importer WordPress plugin that allows you to import the theme demo data Based on One Click D …
Custom Global Variables Developer Profile
1 plugin · 5K total installs
How We Detect Custom Global Variables
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-global-variables/style.css/wp-content/plugins/custom-global-variables/script.js/wp-content/plugins/custom-global-variables/script.jscustom-global-variables/style.css?ver=custom-global-variables/script.js?ver=HTML / DOM Fingerprints
custom-global-variables-stylecustom-global-variables-scriptid="custom-global-variables-table-definitions"cgv[cgv echo $GLOBALS['cgv']['