
Fields Security & Risk Analysis
wordpress.org/plugins/fieldsCreates custom write panels to manage post custom fields.
Is Fields Safe to Use in 2026?
Generally Safe
Score 85/100Fields has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "fields" v0.4.3 exhibits a generally good security posture based on the static analysis. The absence of known CVEs, SQL injection vulnerabilities, and critical taint flows is a strong indicator of secure coding practices. The presence of nonce and capability checks on entry points, along with 100% of SQL queries using prepared statements, further strengthens its security. However, a significant concern lies in the output escaping, with only 15% of outputs being properly escaped. This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially given the presence of 4 shortcodes which can be leveraged by attackers to inject malicious scripts. The analysis also indicates 3 flows with unsanitized paths, which, although not categorized as critical or high severity, warrants investigation and remediation to prevent potential data leakage or manipulation.
Key Concerns
- Low percentage of properly escaped output (15%)
- 3 flows with unsanitized paths
- Bundled outdated jQuery v1.4.2
Fields Security Vulnerabilities
Fields Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Fields Attack Surface
AJAX Handlers 1
Shortcodes 4
WordPress Hooks 10
Maintenance & Trust
Fields Maintenance & Trust
Maintenance Signals
Community Trust
Fields Alternatives
Advanced Custom Fields: Extended
acf-extended
All-in-one enhancement suite that improves WordPress & Advanced Custom Fields.
JSM Show Post Metadata
jsm-show-post-meta
Show post metadata (aka custom fields) in a metabox when editing posts / pages - a great tool for debugging issues with post metadata.
JSM Show User Metadata
jsm-show-user-meta
Show user metadata in a metabox when editing users - a great tool for debugging issues with user metadata.
Easy Post Types and Fields
easy-post-types-fields
Easy Post Types and Fields makes it quick and easy to add custom post types, custom fields, and taxonomies to your WordPress website.
JSM Show Order Metadata for WooCommerce HPOS
jsm-show-order-meta
Show WooCommerce order metadata in a metabox when editing HPOS orders - a great tool for debugging issues with HPOS order metadata.
Fields Developer Profile
2 plugins · 510 total installs
How We Detect Fields
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fields/js/fields.js/wp-content/plugins/fields/js/options.js/wp-content/plugins/fields/js/edit.js/wp-content/plugins/fields/js/import.js/wp-content/plugins/fields/css/options.css/wp-content/plugins/fields/css/edit.css/wp-content/plugins/fields/js/jquery.cookie.jsjs/fields.jsjs/options.jsjs/edit.jsjs/import.jsjs/jquery.cookie.jsjs/fields.js?ver=js/options.js?ver=js/edit.js?ver=js/import.js?ver=css/options.css?ver=css/edit.css?ver=js/jquery.cookie.js?ver=HTML / DOM Fingerprints
fs_boxes_wrapfs_group_fieldsfs_field_datafs_inputfs_add_boxfs_add_groupfs_add_fieldfs_options_wrap+3 moredata-fs-field-typedata-fs-field-namedata-fs-group-namedata-fs-box-keyfsAjaximportStrings