
DA Media CPT Show Custom Fields Security & Risk Analysis
wordpress.org/plugins/damedia-cpt-show-custom-fieldsLightweight plugin to hide or show Custom Fields on the edit page of all public Custom Post Types on your Wordpress installation.
Is DA Media CPT Show Custom Fields Safe to Use in 2026?
Generally Safe
Score 85/100DA Media CPT Show Custom Fields has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'damedia-cpt-show-custom-fields' v1.1.0 demonstrates a generally good security posture based on the provided static analysis. There are no identified entry points that are unprotected, which is a significant strength. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests further contributes to its secure design. The presence of nonce and capability checks, although limited, indicates an awareness of security best practices.
However, the primary concern lies in the output escaping. With 42% of outputs properly escaped, there's a significant risk of Cross-Site Scripting (XSS) vulnerabilities. If user-supplied data or dynamic content is not properly sanitized before being displayed, an attacker could inject malicious scripts. While the taint analysis shows no flows with unsanitized paths, this is likely due to the limited scope of analysis or the absence of such flows in the analyzed code. The plugin's history of zero known vulnerabilities is positive, but this should not be relied upon as a sole indicator of current security, especially given the output escaping issue.
In conclusion, the plugin exhibits strengths in its limited attack surface and secure handling of database operations. The main weakness is the insufficient output escaping, which presents a tangible risk of XSS. It is crucial to address the unescaped outputs to mitigate this vulnerability.
Key Concerns
- Insufficient output escaping detected
DA Media CPT Show Custom Fields Security Vulnerabilities
DA Media CPT Show Custom Fields Release Timeline
DA Media CPT Show Custom Fields Code Analysis
Output Escaping
DA Media CPT Show Custom Fields Attack Surface
WordPress Hooks 6
Maintenance & Trust
DA Media CPT Show Custom Fields Maintenance & Trust
Maintenance Signals
Community Trust
DA Media CPT Show Custom Fields Alternatives
Custom post types, Custom Fields & more
custom-post-types
Custom Post Types, Custom Fields, Custom Taxonomies, Custom Templates, Custom Admin Pages, Custom Admin Notices. Directly from the WP dashboard.
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
Pods – Custom Content Types and Fields
pods
Pods is a framework for creating, managing, and deploying customized content types and fields for any project.
Sydney Toolbox
sydney-toolbox
Registers custom post types and custom fields for the Sydney theme
Hide Admin Menu
hide-admin-menu
Using this plugin, we can hide the admin menu easily.
DA Media CPT Show Custom Fields Developer Profile
1 plugin · 0 total installs
How We Detect DA Media CPT Show Custom Fields
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/damedia-cpt-show-custom-fields/inc/css/damedia-cpt-show-cfs-admin.cssdamedia-cpt-show-custom-fields/inc/css/damedia-cpt-show-cfs-admin.css?ver=HTML / DOM Fingerprints
daml-review-footerdaml-setting-tab-stddata-plugin-name="DAMedia CPT Show Custom Fields"