
Magic Meta Box Security & Risk Analysis
wordpress.org/plugins/magic-meta-boxMagic Meta Box helps you to create easily custom meta boxes fields in post, page and custom post type. You can create repeated group fields and tabs.
Is Magic Meta Box Safe to Use in 2026?
Generally Safe
Score 85/100Magic Meta Box has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The magic-meta-box plugin v2.4.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, using prepared statements for all SQL queries, and having no recorded vulnerabilities (CVEs) or taint flow issues. The presence of a nonce check and capability checks on some entry points is also a positive sign. However, significant concerns arise from the attack surface analysis. With 3 total entry points, 2 of them are unprotected, specifically two AJAX handlers that lack authentication checks. This is a critical weakness that could allow unauthorized users to trigger potentially harmful actions. Furthermore, the plugin has a very low percentage (6%) of properly escaped output, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities, even though no specific taint flows were detected during the static analysis.
Key Concerns
- 2 unprotected AJAX handlers
- Low output escaping percentage (6%)
Magic Meta Box Security Vulnerabilities
Magic Meta Box Release Timeline
Magic Meta Box Code Analysis
Bundled Libraries
Output Escaping
Magic Meta Box Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Magic Meta Box Maintenance & Trust
Maintenance Signals
Community Trust
Magic Meta Box Alternatives
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
Ocean Extra
ocean-extra
The ultimate companion for OceanWP. Adds local Google Fonts, mega menus, site templates, and per-page settings for total design authority.
CubeWP Framework
cubewp-framework
CubeWP is an end-to-end dynamic content framework for WordPress to help you shrink time and cut cost of development up to 90%.
MB Elementor Integration
mb-elementor-integrator
Integrates Meta Box's custom fields with Elementor page builder via dynamic tags.
Attesa Extra
attesa-extra
Add extra features to Attesa WordPress theme
Magic Meta Box Developer Profile
1 plugin · 40 total installs
How We Detect Magic Meta Box
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/magic-meta-box/css/fonts.css/wp-content/plugins/magic-meta-box/css/jquery-ui.min.css/wp-content/plugins/magic-meta-box/css/select2.min.css/wp-content/plugins/magic-meta-box/css/jquery-ui-timepicker-addon.min.css/wp-content/plugins/magic-meta-box/css/metabox.css/wp-content/plugins/magic-meta-box/js/meta-box-map.js/wp-content/plugins/magic-meta-box/js/select2.min.js/wp-content/plugins/magic-meta-box/js/jquery-ui-timepicker-addon.min.js+9 more/wp-content/plugins/magic-meta-box/js/select2.min.js/wp-content/plugins/magic-meta-box/js/jquery-ui-timepicker-addon.min.js/wp-content/plugins/magic-meta-box/js/metabox-gallery.js/wp-content/plugins/magic-meta-box/js/meta-box-image.js/wp-content/plugins/magic-meta-box/js/meta-box-file.js/wp-content/plugins/magic-meta-box/js/metabox.js+1 moreHTML / DOM Fingerprints
tabsMetaboxmetaboxGeneratorTabtableWithTabsmetaboxTablemainMetaDiscriptionmetaDiscriptiondata-tabgs_meta_Ajaxmeta_imagemeta_filegs_metaboxgs_show_hide