
Debug Meta Data Security & Risk Analysis
wordpress.org/plugins/debug-meta-dataCreates a meta-box with meta-data information of a post for all post types. Information with meta key, meta value and its var_dump
Is Debug Meta Data Safe to Use in 2026?
Mostly Safe
Score 79/100Debug Meta Data is generally safe to use. 1 past CVE were resolved. Keep it updated.
The 'debug-meta-data' plugin v1.1.2 exhibits a concerning security posture despite its minimal attack surface and lack of detected taint flows. While the plugin has no direct entry points like AJAX handlers, REST API routes, or shortcodes that are exposed without authentication, and it correctly avoids dangerous functions and raw SQL queries, significant weaknesses are present. A major concern is the complete absence of output escaping, meaning any data rendered by the plugin could be vulnerable to cross-site scripting (XSS) attacks. This lack of sanitization is a critical flaw that could allow attackers to inject malicious scripts into the WordPress admin area or even to end-users, depending on where the meta-data is displayed.
The plugin's vulnerability history is also a red flag. It has a known unpatched medium severity CVE related to Cross-Site Scripting (XSS). The fact that this vulnerability remains unpatched and the plugin has not been updated since October 2020 indicates a lack of ongoing maintenance and security diligence. While the static analysis did not detect any current XSS vulnerabilities in v1.1.2, the historical pattern strongly suggests a recurring weakness in how the plugin handles user-supplied or meta-data. In conclusion, while the plugin's architecture minimizes direct attack vectors and uses prepared statements, the critical flaw of unescaped output coupled with an unpatched XSS vulnerability from its history makes this plugin a significant risk. The lack of maintenance is a major concern for future security.
Key Concerns
- Unpatched CVE found
- Output escaping is not properly implemented
- No capability checks found
- No nonce checks found
Debug Meta Data Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Debug Meta Data <= 1.1.2 - Stored Cross-Site Scripting
Debug Meta Data Code Analysis
Output Escaping
Debug Meta Data Attack Surface
WordPress Hooks 3
Maintenance & Trust
Debug Meta Data Maintenance & Trust
Maintenance Signals
Community Trust
Debug Meta Data Alternatives
MetaViewer – Debug Meta Data
metaviewer-debug-meta-data
View and debug post and user meta data in a clean table format – lightweight, dev-friendly, and works across post types in the WP admin.
Debug User/Post/Options Meta Data
fm-debug-meta-data
Debug User/Post/Options Meta Data plugin lets administrators debug users and posts meta data in a friendly view.
WP Crontrol
wp-crontrol
WP Crontrol enables you to take control of the cron events on your WordPress website.
Query Monitor – The developer tools panel for WordPress
query-monitor
Query Monitor is the developer tools panel for WordPress and WooCommerce.
Debug Bar
debug-bar
Adds a debug menu to the admin bar that shows query, cache, and other helpful debugging information.
Debug Meta Data Developer Profile
6 plugins · 2K total installs
How We Detect Debug Meta Data
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<h3>All Meta Data</h3><strong></strong> => =>