
DX Remove Unused Custom Fields Security & Risk Analysis
wordpress.org/plugins/dx-remove-unused-custom-fieldsDelete the Custom Fields from your postmeta table where assigned posts no longer exist.
Is DX Remove Unused Custom Fields Safe to Use in 2026?
Generally Safe
Score 85/100DX Remove Unused Custom Fields has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "dx-remove-unused-custom-fields" v0.1 exhibits a strong security posture regarding its attack surface, with no apparent AJAX handlers, REST API routes, shortcodes, or cron events. The code also demonstrates good practices by utilizing prepared statements for all SQL queries and implementing at least one nonce check. However, a significant concern arises from the fact that 100% of its output is not properly escaped, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities. While there is no known vulnerability history for this plugin, the lack of proper output escaping is a notable weakness that could be exploited.
Key Concerns
- All output is unescaped
DX Remove Unused Custom Fields Security Vulnerabilities
DX Remove Unused Custom Fields Code Analysis
SQL Query Safety
Output Escaping
DX Remove Unused Custom Fields Attack Surface
WordPress Hooks 1
Maintenance & Trust
DX Remove Unused Custom Fields Maintenance & Trust
Maintenance Signals
Community Trust
DX Remove Unused Custom Fields Alternatives
WP Bulk Delete
wp-bulk-delete
Delete posts, pages, comments, users, taxonomy terms and meta fields in bulk with different powerful filters and conditions.
Optimize Database after Deleting Revisions
rvg-optimize-database
One-click database optimization with precise revision cleanup and flexible scheduling. Speeding up sites since 2011!
Bulk Delete
bulk-delete
Bulk delete posts, pages, users, attachments, and meta fields based on complex bulk conditions & filters.
Another Comments Cleaner
another-comments-cleaner
Delete or trash automatically comments based on status using WP_Cron
OO Cleaner for CFDB7
oo-cleaner-for-cfdb7
Automatically delete old CFDB7 entries after a configurable number of days.
DX Remove Unused Custom Fields Developer Profile
13 plugins · 5K total installs
How We Detect DX Remove Unused Custom Fields
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
ruc-messageruc-posts-list