
Display Post Metadata Security & Risk Analysis
wordpress.org/plugins/display-post-metadataIt is a useful plugin to display the metadata information and custom fields of posts and pages or custom post type. You can either display date, autho …
Is Display Post Metadata Safe to Use in 2026?
Generally Safe
Score 100/100Display Post Metadata has a strong security track record. Known vulnerabilities have been patched promptly.
The "display-post-metadata" plugin version 1.5.5 generally exhibits a good security posture, with no identified entry points into the application that are unprotected. The static analysis reveals a lack of dangerous functions, all SQL queries are properly prepared, and there are no file operations or external HTTP requests, which are all positive indicators. The plugin also has capability checks in place, which is a good practice for restricting access to certain functionalities. However, a significant concern is the low percentage (33%) of properly escaped outputs. This suggests a potential for Cross-Site Scripting (XSS) vulnerabilities, especially if user-supplied data is not consistently handled with adequate sanitization before being displayed.
The vulnerability history indicates one past CVE, which was for Cross-Site Scripting. While there are no currently unpatched vulnerabilities, the historical presence of XSS is a clear warning sign. The fact that this was the only documented vulnerability and it is no longer present is a positive sign, suggesting that developers are responsive to security issues. However, the lingering concern about unescaped output in the current analysis means that even without active CVEs, the potential for XSS remains, making it a notable weakness in the plugin's otherwise strong security foundation.
Key Concerns
- Low percentage of properly escaped output
- Past Cross-Site Scripting (XSS) vulnerability
Display Post Metadata Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Display Post Metadata <= 1.4.0 - Stored Cross-Site Scripting
Display Post Metadata Code Analysis
Output Escaping
Display Post Metadata Attack Surface
WordPress Hooks 6
Maintenance & Trust
Display Post Metadata Maintenance & Trust
Maintenance Signals
Community Trust
Display Post Metadata Alternatives
WP Author, Date and Meta Remover
wp-author-date-and-meta-remover
Don't need the post date and author meta data on your pages? Install WP Author, Date and Meta Remover and its gone. It's that easy!
Metadata Viewer
metadata-viewer
A plugin or theme developer can view metadata by this plugin easily.
Display post meta, term meta, comment meta, and user meta
display-metadata
Displays metadata in a metabox on the creation/editing pages for posts (any CPT), terms (any taxonomy), and users. The metadata is shown in a human-re …
Ascendoor Metadata Manager
ascendoor-metadata-manager
A great plugin to display all metadata related to the posts, pages, custom post types, terms, custom taxonomy terms, users and comments that can be us …
dig Description
dig-description
Just the Meta Description. / 投稿ページやアーカイブページに、ただディスクリプションを設定できるだけのプラグインです。
Display Post Metadata Developer Profile
3 plugins · 2K total installs
How We Detect Display Post Metadata
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/display-post-metadata/css/style.css/wp-content/plugins/display-post-metadata/svg/date.svg/wp-content/plugins/display-post-metadata/svg/user.svg/wp-content/plugins/display-post-metadata/svg/sticky.svg/wp-content/plugins/display-post-metadata/svg/eye.svg/wp-content/plugins/display-post-metadata/svg/comment.svg/wp-content/plugins/display-post-metadata/js/mce-button.js/wp-content/plugins/display-post-metadata/css/mce-button.cssHTML / DOM Fingerprints
display-post-metadatadpm-wrapdate-metaauthor-metasticky-metaviews-metacomment-metadpm-custom-fields+2 moreid="dpm-wrap"window.wp.mce[metadata element="date,author,sticky,views,comments"][metadata element="custom_fields"]