
Gutenberg Custom Fields Security & Risk Analysis
wordpress.org/plugins/gutenberg-custom-fieldsGutenberg Custom Fields allows you to control the content of the Gutenberg edit screen by creating pre-filled templates.
Is Gutenberg Custom Fields Safe to Use in 2026?
Generally Safe
Score 85/100Gutenberg Custom Fields has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the "gutenberg-custom-fields" plugin v1.5.6 exhibits a strong security posture. The code analysis reveals no identified dangerous functions, all SQL queries utilize prepared statements, and output appears to be properly escaped. Furthermore, there are no observed file operations or external HTTP requests, and the plugin does not appear to introduce any significant attack surface through AJAX handlers, REST API routes, shortcodes, or cron events, with a complete lack of unprotected entry points.
The absence of any recorded vulnerabilities in its history, including critical or high-severity issues, further reinforces this positive assessment. This suggests a commitment to secure coding practices by the developers and a consistent track record of stability. The lack of identified taint flows with unsanitized paths also indicates that user-supplied data is likely handled safely.
In conclusion, this plugin appears to be well-developed from a security perspective. The thorough implementation of prepared statements, output escaping, and the absence of exploitable entry points are significant strengths. The clean vulnerability history is also a major positive. While the complete absence of nonce and capability checks on entry points (due to zero entry points) is technically not a weakness in this specific instance, it's a general area to monitor for any future expansions of functionality that might introduce such points.
Gutenberg Custom Fields Security Vulnerabilities
Gutenberg Custom Fields Release Timeline
Gutenberg Custom Fields Code Analysis
Gutenberg Custom Fields Attack Surface
Maintenance & Trust
Gutenberg Custom Fields Maintenance & Trust
Maintenance Signals
Community Trust
Gutenberg Custom Fields Alternatives
Classic Editor
classic-editor
Enables the previous "classic" editor and the old-style Edit Post screen with TinyMCE, Meta Boxes, etc. Supports all plugins that extend this screen.
Starter Templates – AI-Powered Templates for Elementor & Gutenberg
astra-sites
The growing library of 300+ ready-to-use templates that work with all WordPress themes including Astra, Hello, OceanWP, GeneratePress and more
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
Advanced Editor Tools
tinymce-advanced
Extends and enhances the block editor (Gutenberg) and the classic editor (TinyMCE).
Spectra Gutenberg Blocks – Website Builder for the Block Editor
ultimate-addons-for-gutenberg
Power-up Gutenberg with advanced blocks for faster website creation. Build your WordPress website effortlessly using powerful building blocks!
Gutenberg Custom Fields Developer Profile
3 plugins · 140 total installs
How We Detect Gutenberg Custom Fields
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gutenberg-custom-fields/build/index.css/wp-content/plugins/gutenberg-custom-fields/build/index.js/wp-content/plugins/gutenberg-custom-fields/lib/common.php/wp-content/plugins/gutenberg-custom-fields/lib/hacks.php/wp-content/plugins/gutenberg-custom-fields/lib/i18n-script.php/wp-content/plugins/gutenberg-custom-fields/lib/fields-script.php/wp-content/plugins/gutenberg-custom-fields/lib/config-app-script.php/wp-content/plugins/gutenberg-custom-fields/lib/custom-post-type.php+3 moreHTML / DOM Fingerprints
gcf_admin_optionsgcf_datagcf_fields_data/wp-json/gutenberg-custom-fields/v1/templates