
Display Custom Fields Security & Risk Analysis
wordpress.org/plugins/display-custom-fieldsThis plugin allows you to display the value of a custom field on a page or post. Permitted values are raw text, html, javascript, javascript file url, …
Is Display Custom Fields Safe to Use in 2026?
Generally Safe
Score 85/100Display Custom Fields has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "display-custom-fields" plugin v1.1.1 exhibits a strong security posture based on the provided static analysis. The code analysis reveals no dangerous functions, all SQL queries utilize prepared statements, and all outputs are properly escaped. There are no file operations or external HTTP requests, indicating a limited potential for code injection or data exfiltration through these vectors. The absence of any taint analysis findings further suggests a lack of exploitable vulnerabilities within the analyzed code flows.
While the static analysis is positive, the absence of any capability checks or nonce checks on the single shortcode entry point is a notable concern. Shortcodes can be invoked by any logged-in user, and without proper checks, they could potentially be used in conjunction with other vulnerabilities or misconfigurations to perform unauthorized actions. The vulnerability history is also clean, with no recorded CVEs, which is a positive indicator of the plugin's development and maintenance practices.
Overall, the plugin demonstrates good coding practices regarding data handling and protection against common code execution vulnerabilities. However, the lack of authorization checks on its sole entry point presents a potential weakness that could be exploited in specific scenarios. The clean vulnerability history is a strength, but it is crucial to maintain vigilance, especially given the identified lack of authorization on the shortcode.
Key Concerns
- Missing capability checks on shortcode
- Missing nonce checks on shortcode
Display Custom Fields Security Vulnerabilities
Display Custom Fields Code Analysis
Display Custom Fields Attack Surface
Shortcodes 1
Maintenance & Trust
Display Custom Fields Maintenance & Trust
Maintenance Signals
Community Trust
Display Custom Fields Alternatives
Add Custom Fields to Media
add-custom-fields-to-media
Add custom fields to media uploader and access them in template files. Great for copyrights, image meta etc.
Custom Field Builder – WordPress custom fields plugin
custom-field-builder
Custom Field Builder is a powerful and lightweight developer plugin to create custom meta boxes and custom fields for WordPress.
Meta Extension
meta-extensions
Allows adding custom form fields to posts, storing them in custom meta fields. Integrates NGG, WT, and WP-DM.
WP Search Include Meta Fields
wp-search-include-meta-fields
License: GPLv2 or later WordPress plugin to extend default search to include meta fields
Bulk Meta Fields Update
bulk-meta-fields-update
Bulk update or add custom meta fields to any post type using a CSV file with security and logging features.
Display Custom Fields Developer Profile
1 plugin · 10 total installs
How We Detect Display Custom Fields
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/display-custom-fields/display-custom-fields.phpHTML / DOM Fingerprints
Copyright 2014 Tarun Chaudhry @ TeaCii (email : info@TeaCii.com)<script type="text/javascript"><script type="text/javascript" src="<style type="text/css"><link type="text/css" rel="stylesheet" href="