LIQUID TOOLS – Simple Custom Fields & Custom Post Types Security & Risk Analysis

wordpress.org/plugins/liquid-tools

Very simple tool to set up Custom Fields, Custom Post Types, Custom Taxonomies.

90 active installs v1.0.3 PHP + WP 6.0+ Updated Nov 18, 2024
custom-fieldscustom-post-typescustom-taxonomies
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LIQUID TOOLS – Simple Custom Fields & Custom Post Types Safe to Use in 2026?

Generally Safe

Score 92/100

LIQUID TOOLS – Simple Custom Fields & Custom Post Types has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'liquid-tools' v1.0.3 plugin exhibits a very strong security posture. The absence of any recorded vulnerabilities, including CVEs of any severity, is a significant positive indicator. Furthermore, the code analysis reveals no critical security flaws such as dangerous functions, unsanitized taint flows, or raw SQL queries. The plugin also demonstrates good practices with a high percentage of properly escaped output and the presence of nonce checks. However, the lack of capability checks on any entry points, while currently not exploited (as there are no entry points in the first place), represents a potential future risk if the plugin's attack surface were to expand. The plugin's current design appears to be highly secure, but this assessment is based solely on the provided data for this specific version.

Vulnerabilities
None known

LIQUID TOOLS – Simple Custom Fields & Custom Post Types Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

LIQUID TOOLS – Simple Custom Fields & Custom Post Types Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
221 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

93% escaped237 total outputs
Attack Surface

LIQUID TOOLS – Simple Custom Fields & Custom Post Types Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actioninitliquid-tools.php:121
filterpre_update_option_liquid_tools_post_typesliquid-tools.php:394
filterpre_update_option_liquid_tools_taxonomiesliquid-tools.php:395
filterpre_update_option_liquid_tools_custom_fieldsliquid-tools.php:396
actionadmin_menuliquid-tools.php:450
actionadmin_initliquid-tools.php:451
actionadmin_enqueue_scriptsliquid-tools.php:468
actionadmin_noticesliquid-tools.php:485
actionadmin_headliquid-tools.php:518
actionadd_meta_boxesliquid-tools.php:683
actionsave_postliquid-tools.php:740
Maintenance & Trust

LIQUID TOOLS – Simple Custom Fields & Custom Post Types Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 18, 2024
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs90
Developer Profile

LIQUID TOOLS – Simple Custom Fields & Custom Post Types Developer Profile

lqd

9 plugins · 16K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
617 days
View full developer profile
Detection Fingerprints

How We Detect LIQUID TOOLS – Simple Custom Fields & Custom Post Types

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/liquid-tools/css/liquid-tools.css/wp-content/plugins/liquid-tools/js/liquid-tools.js
Script Paths
/wp-content/plugins/liquid-tools/js/liquid-tools.js
Version Parameters
liquid-tools/css/liquid-tools.css?ver=liquid-tools/js/liquid-tools.js?ver=

HTML / DOM Fingerprints

CSS Classes
liquid-tools
REST Endpoints
/wp-json/liquid-tools/
FAQ

Frequently Asked Questions about LIQUID TOOLS – Simple Custom Fields & Custom Post Types