
Entity Viewer Security & Risk Analysis
wordpress.org/plugins/entity-viewerDisplays properties and custom fields of WordPress entities (posts, users, terms, comments) for debugging/development purposes.
Is Entity Viewer Safe to Use in 2026?
Generally Safe
Score 92/100Entity Viewer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The entity-viewer plugin v0.5.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and has no recorded vulnerability history, suggesting a generally stable codebase. However, significant concerns arise from the static analysis. The plugin exposes a single AJAX handler without any authentication or authorization checks, creating a direct attack vector. Furthermore, the presence of the `unserialize` function, especially in conjunction with an unprotected entry point, is a critical red flag as it can lead to arbitrary code execution if user-supplied data is unserialized without proper validation. While taint analysis found no issues, this might be due to the limited scope or the nature of the input, and the `unserialize` vulnerability remains a potent threat. The lack of capability checks on the AJAX endpoint is also a notable weakness.
Key Concerns
- AJAX handler without auth check
- Dangerous function: unserialize
- Nonce check missing on AJAX
- Capability check missing
Entity Viewer Security Vulnerabilities
Entity Viewer Release Timeline
Entity Viewer Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Entity Viewer Attack Surface
AJAX Handlers 1
WordPress Hooks 11
Maintenance & Trust
Entity Viewer Maintenance & Trust
Maintenance Signals
Community Trust
Entity Viewer Alternatives
CubeWP Framework
cubewp-framework
CubeWP is an end-to-end dynamic content framework for WordPress to help you shrink time and cut cost of development up to 90%.
PT Theme Addon
pt-theme-addon
Plugin to add team, testimonial portfolio and clients custom post type. Each post type has its widget and shortcode to use in theme.
Meta Content
meta
A meta box which helps us to add content or scripts to any part of the website, on each individual post/page. Easy to Implement with Shortcode.
Business Era Extension
business-era-extension
Plugin to extend features of Business Era Theme. This plugin registers custom post types, widgets and custom fields for the Business Era theme.
Theme Toolkit
theme-toolkit
Theme toolkit is a plugin to register custom post types, widgets and shortcodes to add additional feature and functionality to any WordPress theme.
Entity Viewer Developer Profile
2 plugins · 400 total installs
How We Detect Entity Viewer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/entity-viewer/assets/css/main.css/wp-content/plugins/entity-viewer/assets/js/main.js/wp-content/plugins/entity-viewer/assets/js/main.jsentity-viewer/assets/css/main.css?ver=entity-viewer/assets/js/main.js?ver=HTML / DOM Fingerprints
ev-entity-viewer-tab<!-- ev-track-field -->data-ev-track-fieldwindow.entityViewer