
Custom Page Attributes Security & Risk Analysis
wordpress.org/plugins/custom-page-attributesCustomize the parent page dropdown in the page attributes meta box to show only top-level ones with no parent.
Is Custom Page Attributes Safe to Use in 2026?
Generally Safe
Score 85/100Custom Page Attributes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis, the "custom-page-attributes" plugin v1.0 exhibits a strong security posture with no apparent vulnerabilities detected. The absence of identified dangerous functions, SQL queries not using prepared statements, and a complete lack of output that isn't properly escaped are all positive indicators. Furthermore, the plugin does not perform file operations or external HTTP requests, reducing its potential attack surface. The plugin also has zero recorded CVEs, suggesting a history of secure development or prompt patching if issues have arisen in the past.
While the static analysis results are highly favorable, it's important to note the complete absence of taint analysis and the lack of any detected capability or nonce checks. This suggests that either the analyzed code was very simple with no user-controllable input paths, or the analysis itself might have been limited in scope, potentially missing subtle vulnerabilities. The fact that there are no entry points without authentication checks is excellent, but the absence of any nonce or capability checks means that if any such entry points were to be introduced in future versions, they might be inherently insecure by default.
In conclusion, "custom-page-attributes" v1.0 currently appears to be a secure plugin. Its development practices, as reflected in the static analysis, are robust. However, the lack of comprehensive taint analysis and the complete absence of nonce and capability checks, while not indicative of current vulnerabilities, represent a potential weakness if the plugin's functionality expands in the future, and suggests that rigorous testing should continue.
Key Concerns
- No capability checks found
- No nonce checks found
- Taint analysis results missing
Custom Page Attributes Security Vulnerabilities
Custom Page Attributes Code Analysis
Custom Page Attributes Attack Surface
WordPress Hooks 1
Maintenance & Trust
Custom Page Attributes Maintenance & Trust
Maintenance Signals
Community Trust
Custom Page Attributes Alternatives
Country & Phone Field Contact Form 7
country-phone-field-contact-form-7
Add country drop down with flags and phone number with country phone extension fields in contact form 7.
Country State City Dropdown CF7
country-state-city-auto-dropdown
Add country state city dropdown CF7 in contact form 7 plugin. In PRO you can use these features on any type of form.
Cities Shipping Zones for WooCommerce
cities-shipping-zones-for-woocommerce
WooCommerce plugin for turning the state field into a dropdown city field. To be used as Shipping Zones.
Min Max Step Quantity Limits Manager for WooCommerce
product-quantity-for-woocommerce
Define a min/max, step, decimal & default quantity for products, show a dropdown and much more on WooCommerce stores.
Navigation menu as Dropdown Widget
navigation-menu-as-dropdown-widget
WordPress plugin which provides a widget with a clickable dropdown of a WordPress navigation menu. It supports one level of parent-child menu's.
Custom Page Attributes Developer Profile
1 plugin · 0 total installs
How We Detect Custom Page Attributes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.