JSM Show Term Metadata Security & Risk Analysis

wordpress.org/plugins/jsm-show-term-meta

Show term metadata in a metabox when editing terms - a great tool for debugging issues with term metadata.

800 active installs v4.8.0 PHP 7.4.33+ WP 6.0+ Updated Mar 11, 2026
categoriesmetadatatagstaxonomyterms
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is JSM Show Term Metadata Safe to Use in 2026?

Generally Safe

Score 100/100

JSM Show Term Metadata has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 23d ago
Risk Assessment

The static analysis of the jsm-show-term-meta plugin v4.8.0 reveals a strong security posture with no identified attack surface, dangerous functions, or vulnerable code patterns. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits potential entry points for malicious actors. Furthermore, all identified SQL queries utilize prepared statements, and output escaping is consistently applied, indicating good coding practices. The taint analysis also shows no concerning flows, reinforcing the impression of secure code.

The vulnerability history further bolsters this assessment, with zero recorded CVEs of any severity. This lack of historical vulnerabilities, combined with the clean static analysis, suggests a well-maintained and secure plugin. The plugin's strengths lie in its minimal attack surface and adherence to secure coding principles like prepared statements and output escaping.

While the current data presents a highly positive security outlook, it's important to acknowledge that a complete security assessment requires a broader scope, including a review of the plugin's purpose and its interactions with other WordPress components. However, based solely on the provided static analysis and vulnerability history, jsm-show-term-meta v4.8.0 appears to be a very secure plugin.

Vulnerabilities
None known

JSM Show Term Metadata Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

JSM Show Term Metadata Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

JSM Show Term Metadata Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioninitjsm-show-term-meta.php:50
actioninitjsm-show-term-meta.php:51
Maintenance & Trust

JSM Show Term Metadata Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 11, 2026
PHP min version7.4.33
Downloads31K

Community Trust

Rating0/100
Number of ratings0
Active installs800
Developer Profile

JSM Show Term Metadata Developer Profile

JS Morisset

31 plugins · 33K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
12 days
View full developer profile
Detection Fingerprints

How We Detect JSM Show Term Metadata

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jsm-show-term-meta/assets/js/jsm-show-term-meta.js/wp-content/plugins/jsm-show-term-meta/assets/css/jsm-show-term-meta.css
Version Parameters
jsm-show-term-meta/assets/js/jsm-show-term-meta.js?ver=jsm-show-term-meta/assets/css/jsm-show-term-meta.css?ver=

HTML / DOM Fingerprints

CSS Classes
jsm-stm-metabox
Data Attributes
data-jsm-stm-term-iddata-jsm-stm-tax-iddata-jsm-stm-term-taxonomy
JS Globals
JsmStmAdmin
FAQ

Frequently Asked Questions about JSM Show Term Metadata