
Edit Profile Fields Security & Risk Analysis
wordpress.org/plugins/edit-profile-fieldsCreate, show, hide and delete custom contact info fields on your users profiles.
Is Edit Profile Fields Safe to Use in 2026?
Generally Safe
Score 85/100Edit Profile Fields has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "edit-profile-fields" v1.0.0 plugin presents a mixed security posture. On the positive side, its static analysis reveals no identified attack surface through AJAX, REST API, shortcodes, or cron events, and no dangerous functions, file operations, or external HTTP requests were detected. The vast majority of output is properly escaped, and capability checks are in place, indicating an effort towards secure coding practices. However, a significant concern arises from the SQL queries; all 17 queries are executed without prepared statements, which is a major security risk, particularly in the context of user-submitted data. The absence of nonce checks, while not directly tied to an exposed attack vector in this analysis, is a common security oversight that could be exploited if an attack surface were to be discovered. The plugin's vulnerability history is clean, with no known CVEs, which is a strong positive indicator. Despite the lack of direct vulnerabilities in its history, the raw SQL queries represent a tangible and exploitable risk that needs immediate attention.
Key Concerns
- All SQL queries lack prepared statements
- No nonce checks implemented
Edit Profile Fields Security Vulnerabilities
Edit Profile Fields Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Edit Profile Fields Attack Surface
WordPress Hooks 3
Maintenance & Trust
Edit Profile Fields Maintenance & Trust
Maintenance Signals
Community Trust
Edit Profile Fields Alternatives
Custom User Profile Photo
custom-user-profile-photo
Add a customized User Profile photo to a WordPress user profile.
Profile Picture
profile-picture
Set a profile picture as your wish using media upload.
Tismy User Profile Upload
tismy-user-profile-upload
Upload your own user profile picture rather than falling back to the default or having your users create a Gravatar account.
Plugin Name: Buddypress profile view from admin
buddypress-profile-view-from-admin
This plugin allows admin user to view buddypress profile from admin amd will not work without buddypress.
Dashboard User profile Detais-(DUPD)
dashboard-user-profile-detais-dupd
A smart, easy way to add Dashboard User Profile Widget to your Wordpress Site.
Edit Profile Fields Developer Profile
1 plugin · 10 total installs
How We Detect Edit Profile Fields
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/edit-profile-fields/includes/options.css