
Debug User/Post/Options Meta Data Security & Risk Analysis
wordpress.org/plugins/fm-debug-meta-dataDebug User/Post/Options Meta Data plugin lets administrators debug users and posts meta data in a friendly view.
Is Debug User/Post/Options Meta Data Safe to Use in 2026?
Generally Safe
Score 85/100Debug User/Post/Options Meta Data has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The fm-debug-meta-data plugin, version 1.0.0, presents significant security concerns despite its clean vulnerability history. The static analysis reveals a concerning lack of security best practices, most notably the presence of an unprotected AJAX handler. This handler is a direct entry point into the plugin's functionality that lacks any authentication or authorization checks, making it a prime target for attackers. Furthermore, the use of the `unserialize` function without proper validation is a critical vulnerability, as it can lead to remote code execution if an attacker can control the data being unserialized. The output escaping is also completely absent, meaning any data displayed back to the user is vulnerable to cross-site scripting (XSS) attacks. While the plugin uses prepared statements for its SQL queries and has no recorded CVEs, these positive aspects are heavily outweighed by the critical security flaws identified in the code analysis. The absence of known vulnerabilities could be due to the plugin's obscurity or a lack of thorough security auditing in the past, rather than inherent security strength.
Key Concerns
- Unprotected AJAX handler
- Use of unserialize function
- No output escaping
- No nonce checks
- No capability checks
Debug User/Post/Options Meta Data Security Vulnerabilities
Debug User/Post/Options Meta Data Code Analysis
Dangerous Functions Found
Output Escaping
Debug User/Post/Options Meta Data Attack Surface
AJAX Handlers 1
WordPress Hooks 2
Maintenance & Trust
Debug User/Post/Options Meta Data Maintenance & Trust
Maintenance Signals
Community Trust
Debug User/Post/Options Meta Data Alternatives
Premmerce Dev Tools
premmerce-dev-tools
This plugin is created to facilitate the development, testing and debugging of the code on the WordPress platform and to quickly create the demo data …
Freesoul Deactivate Plugins – Disable plugins on individual WordPress pages
freesoul-deactivate-plugins
Load plugins only where you need them. No bloat, no conflicts, more speed. Deactivate plugins where they don't add anything useful.
Fatal Error Notify
fatal-error-notify
Receive email notifications when errors occur on your WordPress site.
WP Safe Mode
wp-safe-mode
Disable plugins or switch themes for just you or the whole site for debugging, troubleshooting or accessing and restoring a broken website.
Debug Bar Console
debug-bar-console
Adds a PHP/SQL console to the Debug Bar. Requires the Debug Bar plugin.
Debug User/Post/Options Meta Data Developer Profile
2 plugins · 20 total installs
How We Detect Debug User/Post/Options Meta Data
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fm-debug-meta-data/css/jquery-ui.min.css/wp-content/plugins/fm-debug-meta-data/css/style.css/wp-content/plugins/fm-debug-meta-data/js/custom.js/wp-content/plugins/fm-debug-meta-data/js/custom.jsfm-debug-custom?ver=1.0.0HTML / DOM Fingerprints
folder-treemeta-data-valuekey-treeval-treecss-treeviewdm-main-keydm-main-valexpand-groupid="item-for="item-for="expand-id="expand-class="expand"jquery-ui-tabs