
Juiz User Custom Meta Security & Risk Analysis
wordpress.org/plugins/juiz-user-customAllows administrator to configure some extra fields (user meta) for users. With these new fields, make a rich authors or users page, for example.
Is Juiz User Custom Meta Safe to Use in 2026?
Generally Safe
Score 85/100Juiz User Custom Meta has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "juiz-user-custom" v0.5 plugin exhibits a mixed security posture. On the positive side, it has a very small attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events. All SQL queries are properly prepared, and there are no file operations or external HTTP requests, which are excellent practices. However, significant concerns arise from the code signals. The presence of dangerous functions like `unserialize` and `create_function`, coupled with a very low percentage of properly escaped output (only 9%), indicates a high risk of code injection and cross-site scripting (XSS) vulnerabilities. Furthermore, the taint analysis revealing two flows with unsanitized paths, even if not classified as critical or high severity in this specific analysis, is a strong indicator of potential vulnerabilities where user-supplied data is not adequately validated before being used in sensitive operations. The absence of any recorded vulnerability history is a positive sign, suggesting that past versions may not have had exploitable flaws. However, this does not negate the risks identified in the static and taint analysis of the current version.
Key Concerns
- Dangerous functions detected (unserialize, create_function)
- Low output escaping (9%)
- Taint flows with unsanitized paths (2)
- No nonce checks
- No capability checks
Juiz User Custom Meta Security Vulnerabilities
Juiz User Custom Meta Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Juiz User Custom Meta Attack Surface
WordPress Hooks 8
Maintenance & Trust
Juiz User Custom Meta Maintenance & Trust
Maintenance Signals
Community Trust
Juiz User Custom Meta Alternatives
JSM Show User Metadata
jsm-show-user-meta
Show user metadata in a metabox when editing users - a great tool for debugging issues with user metadata.
Change Author
change-author
This plugin lets you assign non-authors as post author.
WP Custom Author Image
author-image
Lets you easily add WP Custom Author Images on your site.
Get User Custom Field Values
get-user-custom-field-values
Use widgets, shortcodes, and/or template tags to easily retrieve and display custom field values for users.
Dynamic Field for Elementor Forms – Populate Anything
dynamic-field-for-elementor-forms
Pull data from URL Query Parameter, posts, users, terms, Database, CSV, or custom sources and display them directly inside your forms.
Juiz User Custom Meta Developer Profile
6 plugins · 5K total installs
How We Detect Juiz User Custom Meta
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/juiz-user-custom/css/juiz-admin.cssHTML / DOM Fingerprints
form-tableJUIZ_USER_CUSTOM_SLUGjuiz_user_meta_instance