
JSM Show Post Metadata Security & Risk Analysis
wordpress.org/plugins/jsm-show-post-metaShow post metadata (aka custom fields) in a metabox when editing posts / pages - a great tool for debugging issues with post metadata.
Is JSM Show Post Metadata Safe to Use in 2026?
Generally Safe
Score 99/100JSM Show Post Metadata has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of jsm-show-post-meta v4.8.0 shows a very clean codebase with no identified dangerous functions, SQL queries not using prepared statements, or unescaped output. Furthermore, the attack surface is reported as zero, with no AJAX handlers, REST API routes, shortcodes, or cron events. Taint analysis also reveals no identified vulnerabilities. This suggests strong adherence to secure coding practices within this specific version.
However, the plugin has a history of known vulnerabilities, with a total of one CVE recorded. While this vulnerability is currently patched and not critical, the presence of a past 'Missing Authorization' vulnerability is a significant concern. This historical pattern indicates a potential weakness in how user permissions are handled, even if it has been addressed in subsequent updates. It suggests that developers should remain vigilant in thoroughly auditing authorization mechanisms.
Overall, the current version of jsm-show-post-meta v4.8.0 appears secure based on static analysis. The absence of immediate risks in the code itself is a positive sign. Nevertheless, the historical vulnerability, specifically related to missing authorization, warrants a degree of caution and reinforces the importance of keeping the plugin updated and regularly reviewing its security posture.
Key Concerns
- Past Missing Authorization vulnerability
- 1 known CVE
JSM Show Post Metadata Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
JSM Show Post Metadata <= 4.6.0 - Missing Authorization
JSM Show Post Metadata Code Analysis
JSM Show Post Metadata Attack Surface
WordPress Hooks 2
Maintenance & Trust
JSM Show Post Metadata Maintenance & Trust
Maintenance Signals
Community Trust
JSM Show Post Metadata Alternatives
JSM Show User Metadata
jsm-show-user-meta
Show user metadata in a metabox when editing users - a great tool for debugging issues with user metadata.
JSM Show Order Metadata for WooCommerce HPOS
jsm-show-order-meta
Show WooCommerce order metadata in a metabox when editing HPOS orders - a great tool for debugging issues with HPOS order metadata.
JSM Show Comment Metadata
jsm-show-comment-meta
Show comment metadata in a metabox when editing comments - a great tool for debugging issues with comment metadata.
Post Types Order
post-types-order
Sort posts and custom post type objects using a drag-and-drop, sortable JavaScript AJAX interface, or through the default WordPress dashboard
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
JSM Show Post Metadata Developer Profile
31 plugins · 33K total installs
How We Detect JSM Show Post Metadata
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/jsm-show-post-meta/css/jsm-show-post-meta.css/wp-content/plugins/jsm-show-post-meta/js/jsm-show-post-meta.js/wp-content/plugins/jsm-show-post-meta/js/jsm-show-post-meta.jsjsm-show-post-meta/css/jsm-show-post-meta.css?ver=jsm-show-post-meta/js/jsm-show-post-meta.js?ver=HTML / DOM Fingerprints
jsm-post-meta-wrapperdata-jsm-spm-post-iddata-jsm-spm-post-typedata-jsm-spm-noncejsm_spm_data