iG:Custom Metaboxes Security & Risk Analysis

wordpress.org/plugins/ig-custom-metaboxes

A WordPress plugin to provide an object oriented and clean API for creating custom meta-boxes on wp-admin post_type add/edit screens.

10 active installs v1.0 PHP + WP 4.0+ Updated Feb 24, 2015
admincustom-fieldlibrarymetametabox
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is iG:Custom Metaboxes Safe to Use in 2026?

Generally Safe

Score 85/100

iG:Custom Metaboxes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "ig-custom-metaboxes" v1.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code demonstrates good security practices, with all detected SQL queries utilizing prepared statements and a high percentage of output being properly escaped. The presence of nonce and capability checks, although minimal in number, suggests an awareness of security fundamentals.

The analysis indicates no critical or high severity taint flows, and there are no known vulnerabilities (CVEs) associated with this plugin, either historical or current. This lack of recorded vulnerabilities is a positive sign, suggesting either diligent development practices or a limited scope of functionality that hasn't attracted malicious attention.

While the plugin appears secure in its current version based on this data, it's important to note that a zero attack surface doesn't necessarily equate to zero risk, especially if future versions introduce new features. The strengths lie in the absence of overt vulnerabilities and the proper handling of SQL and output. The main weakness, if it can be called that with the current data, is the very limited scope of analysis provided (zero taint flows analyzed). A comprehensive assessment would ideally include more extensive taint analysis to confirm the absence of subtle vulnerabilities.

Vulnerabilities
None known

iG:Custom Metaboxes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

iG:Custom Metaboxes Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
67 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped71 total outputs
Attack Surface

iG:Custom Metaboxes Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filterig-cmf-template-color-fieldclasses\color-field.php:36
actionadmin_enqueue_scriptsclasses\helper.php:75
actionsave_postclasses\metabox.php:257
Maintenance & Trust

iG:Custom Metaboxes Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedFeb 24, 2015
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

iG:Custom Metaboxes Developer Profile

Namith Jawahar

59 plugins · 50K total installs

71
trust score
Avg Security Score
89/100
Avg Patch Time
405 days
View full developer profile
Detection Fingerprints

How We Detect iG:Custom Metaboxes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ig-custom-metaboxes/assets/js/ig-custom-metaboxes-admin.js
Script Paths
/wp-content/plugins/ig-custom-metaboxes/assets/js/ig-custom-metaboxes-admin.js
Version Parameters
ig-custom-metaboxes/assets/js/ig-custom-metaboxes-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
ig-cmf-input-color
Data Attributes
data-ig-custom-metaboxes-id
JS Globals
window.IG_CUSTOM_METABOXES_PLUGIN_ID
FAQ

Frequently Asked Questions about iG:Custom Metaboxes