
Metabase – Post & User Meta Editor Security & Risk Analysis
wordpress.org/plugins/metabase-post-user-meta-editorManage post meta, custom post type meta and user meta of your WordPress site.
Is Metabase – Post & User Meta Editor Safe to Use in 2026?
Generally Safe
Score 100/100Metabase – Post & User Meta Editor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Metabase Post User Meta Editor plugin version 0.8.1 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries, has a low number of output operations with a high percentage properly escaped, and includes a nonce check and capability check for its single entry point. There are no known vulnerabilities or CVEs associated with this plugin, and it does not perform file operations or external HTTP requests.
However, a significant concern arises from the presence of one AJAX handler that lacks authentication checks. This unprotected entry point could potentially be exploited by an attacker to interact with the plugin's functionality without proper authorization. While taint analysis and vulnerability history are clean, the unprotected AJAX handler represents a direct and exploitable attack vector that, if not addressed, could lead to unauthorized actions or information disclosure. The plugin's small attack surface is a mitigating factor, but the lack of authorization on an entry point remains a critical weakness.
Key Concerns
- Unprotected AJAX handler
Metabase – Post & User Meta Editor Security Vulnerabilities
Metabase – Post & User Meta Editor Code Analysis
Output Escaping
Metabase – Post & User Meta Editor Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
Metabase – Post & User Meta Editor Maintenance & Trust
Maintenance Signals
Community Trust
Metabase – Post & User Meta Editor Alternatives
Custom Metadata Manager
custom-metadata
An easy way to add custom fields to your object types (post, pages, custom post types, users)
Metadata Viewer
metadata-viewer
A plugin or theme developer can view metadata by this plugin easily.
Cleanup Duplicate Meta
cleanup-duplicate-meta
Cleanup Duplicate Meta gives you a tool to check for and delete duplicate Post and/or User Meta entries in the database tables.
PureDevs Any Meta Inspector
puredevs-any-meta-inspector
PureDevs Any Meta Inspector shows all the meta keys and their unserialized values in a metabox for posts, pages, terms, comments, and users.
MetaViewer – Debug Meta Data
metaviewer-debug-meta-data
View and debug post and user meta data in a clean table format – lightweight, dev-friendly, and works across post types in the WP admin.
Metabase – Post & User Meta Editor Developer Profile
4 plugins · 470 total installs
How We Detect Metabase – Post & User Meta Editor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/metabase-post-user-meta-editor/resources/css/admin.css/wp-content/plugins/metabase-post-user-meta-editor/resources/js/app.jsmetabase-post-user-meta-editor/resources/css/admin.css?ver=metabase-post-user-meta-editor/resources/js/app.js?ver=HTML / DOM Fingerprints
metabase-meta-box-wrappermetabase-meta-field-inputmetabase-meta-key-inputmetabase-edit-metametabase-delete-meta<!-- The code that runs during plugin activation. --><!-- The code that runs during plugin deactivation. --><!-- Begins execution of the plugin. --><!-- The admin-specific functionality of the plugin. -->+3 moredata-noncedata-meta-typedata-objectdata-field-keyMetabasemetabase