JSM Show Post Metadata Security & Risk Analysis

wordpress.org/plugins/jsm-show-post-meta

Show post metadata (aka custom fields) in a metabox when editing posts / pages - a great tool for debugging issues with post metadata.

10K active installs v4.8.0 PHP 7.4.33+ WP 6.0+ Updated Mar 11, 2026
custom-fieldsinspectormetadatapost-typesposts
99
A · Safe
CVEs total1
Unpatched0
Last CVEJan 24, 2025
Safety Verdict

Is JSM Show Post Metadata Safe to Use in 2026?

Generally Safe

Score 99/100

JSM Show Post Metadata has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 24, 2025Updated 23d ago
Risk Assessment

The static analysis of jsm-show-post-meta v4.8.0 shows a very clean codebase with no identified dangerous functions, SQL queries not using prepared statements, or unescaped output. Furthermore, the attack surface is reported as zero, with no AJAX handlers, REST API routes, shortcodes, or cron events. Taint analysis also reveals no identified vulnerabilities. This suggests strong adherence to secure coding practices within this specific version.

However, the plugin has a history of known vulnerabilities, with a total of one CVE recorded. While this vulnerability is currently patched and not critical, the presence of a past 'Missing Authorization' vulnerability is a significant concern. This historical pattern indicates a potential weakness in how user permissions are handled, even if it has been addressed in subsequent updates. It suggests that developers should remain vigilant in thoroughly auditing authorization mechanisms.

Overall, the current version of jsm-show-post-meta v4.8.0 appears secure based on static analysis. The absence of immediate risks in the code itself is a positive sign. Nevertheless, the historical vulnerability, specifically related to missing authorization, warrants a degree of caution and reinforces the importance of keeping the plugin updated and regularly reviewing its security posture.

Key Concerns

  • Past Missing Authorization vulnerability
  • 1 known CVE
Vulnerabilities
1

JSM Show Post Metadata Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-24589medium · 4.3Missing Authorization

JSM Show Post Metadata <= 4.6.0 - Missing Authorization

Jan 24, 2025 Patched in 4.6.1 (5d)
Code Analysis
Analyzed Mar 16, 2026

JSM Show Post Metadata Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

JSM Show Post Metadata Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioninitjsm-show-post-meta.php:50
actioninitjsm-show-post-meta.php:51
Maintenance & Trust

JSM Show Post Metadata Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 11, 2026
PHP min version7.4.33
Downloads250K

Community Trust

Rating100/100
Number of ratings12
Active installs10K
Developer Profile

JSM Show Post Metadata Developer Profile

JS Morisset

31 plugins · 33K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
12 days
View full developer profile
Detection Fingerprints

How We Detect JSM Show Post Metadata

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jsm-show-post-meta/css/jsm-show-post-meta.css/wp-content/plugins/jsm-show-post-meta/js/jsm-show-post-meta.js
Script Paths
/wp-content/plugins/jsm-show-post-meta/js/jsm-show-post-meta.js
Version Parameters
jsm-show-post-meta/css/jsm-show-post-meta.css?ver=jsm-show-post-meta/js/jsm-show-post-meta.js?ver=

HTML / DOM Fingerprints

CSS Classes
jsm-post-meta-wrapper
Data Attributes
data-jsm-spm-post-iddata-jsm-spm-post-typedata-jsm-spm-nonce
JS Globals
jsm_spm_data
FAQ

Frequently Asked Questions about JSM Show Post Metadata