
Meta By Path Security & Risk Analysis
wordpress.org/plugins/meta-by-pathMeta By Path facilitates for easily replacing an existing value inside a meta content with a new one. Also, it can create new meta names and propertie …
Is Meta By Path Safe to Use in 2026?
Generally Safe
Score 85/100Meta By Path has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "meta-by-path" plugin v1.0.2 presents a mixed security posture. While it boasts a lack of historical vulnerabilities and no critical or high severity taint flows, significant concerns arise from its code analysis. The plugin has a notable number of SQL queries that are not prepared, which could expose the database to SQL injection if any of the inputs used in these queries are not strictly sanitized elsewhere. Furthermore, the presence of an unprotected AJAX handler is a critical security oversight, providing a direct, unauthenticated entry point for potential attackers to exploit. The limited capability checks and a moderate percentage of unescaped output further contribute to a less robust security profile than ideal for a plugin with direct user interaction points.
Despite the absence of known CVEs and critical taint issues, the identified code-level weaknesses, particularly the unprotected AJAX endpoint and the prevalence of non-prepared SQL queries, necessitate caution. The lack of a vulnerability history, while positive, does not negate the risks posed by the current code. Developers should prioritize addressing the unprotected AJAX handler and implementing prepared statements for all database queries. The plugin exhibits strengths in its limited attack surface beyond AJAX and absence of file operations or external requests, but these are overshadowed by the direct security risks identified in the current analysis.
Key Concerns
- Unprotected AJAX handler
- SQL queries not using prepared statements
- Missing capability checks
- Moderate percentage of unescaped output
Meta By Path Security Vulnerabilities
Meta By Path Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Meta By Path Attack Surface
AJAX Handlers 3
WordPress Hooks 4
Maintenance & Trust
Meta By Path Maintenance & Trust
Maintenance Signals
Community Trust
Meta By Path Alternatives
Simple SEO Meta
simple-seo-metadata
Edit meta description, meta keywords and title for each page, post, post type.
Meta Tag Manager
meta-tag-manager
Easily add and manage custom meta tags to various parts of your site or on individual posts, such as Yahoo and Google verification tags.
Basic SEO Pack
basic-seo-pack
Simple but complete SEO Pack to make your site SEO Friendly. Quick way to add meta tags to your post and pages using WP custom fields.
Simple Meta Tags
simple-meta-tags
Allows you to set global meta tags and customize on each individual page/post. Please Note: Does not support custom post types
Auto SEO
auto-seo
Auto SEO is a quick, simple way to add title, meta keywords, and meta descriptions to your site all at one from a single page.
Meta By Path Developer Profile
7 plugins · 140 total installs
How We Detect Meta By Path
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
mbp-form-tableall-dataonclick="WPMBPApp.deleteMetaInfoWPMBPApp.deleteMetaInfo/wp-json/wp/v2/posts