
Metadata Viewer Security & Risk Analysis
wordpress.org/plugins/metadata-viewerA plugin or theme developer can view metadata by this plugin easily.
Is Metadata Viewer Safe to Use in 2026?
Generally Safe
Score 100/100Metadata Viewer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The metadata-viewer plugin version 2.1.1 exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the attack surface. Furthermore, the analysis indicates all SQL queries utilize prepared statements, and there are no file operations or external HTTP requests, which are common sources of vulnerabilities. The presence of capability checks is a positive sign for access control.
However, a significant concern arises from the output escaping analysis, where only 48% of outputs are properly escaped. This suggests a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is reflected in the output without adequate sanitization. The lack of nonce checks on any entry points, while limited by the small attack surface, could be a concern if new entry points were to be introduced in future versions.
The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the apparent lack of critical issues in the static analysis (no dangerous functions, no critical taint flows), suggests a well-maintained codebase for its current state. Despite the positive historical and static analysis indicators, the unescaped output remains the primary actionable security concern.
Key Concerns
- Low output escaping percentage
Metadata Viewer Security Vulnerabilities
Metadata Viewer Code Analysis
Output Escaping
Metadata Viewer Attack Surface
WordPress Hooks 10
Maintenance & Trust
Metadata Viewer Maintenance & Trust
Maintenance Signals
Community Trust
Metadata Viewer Alternatives
Custom Metadata Manager
custom-metadata
An easy way to add custom fields to your object types (post, pages, custom post types, users)
PureDevs Any Meta Inspector
puredevs-any-meta-inspector
PureDevs Any Meta Inspector shows all the meta keys and their unserialized values in a metabox for posts, pages, terms, comments, and users.
Ascendoor Metadata Manager
ascendoor-metadata-manager
A great plugin to display all metadata related to the posts, pages, custom post types, terms, custom taxonomy terms, users and comments that can be us …
View User Metadata
view-user-metadata
A lightweight plugin that allows you to view user metadata, export them CSV or JSON, or delete key/value pairs.
Cleanup Duplicate Meta
cleanup-duplicate-meta
Cleanup Duplicate Meta gives you a tool to check for and delete duplicate Post and/or User Meta entries in the database tables.
Metadata Viewer Developer Profile
1 plugin · 300 total installs
How We Detect Metadata Viewer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/metadata-viewer/assets/admin/js/script.js/wp-content/plugins/metadata-viewer/assets/admin/js/highlight.js/wp-content/plugins/metadata-viewer/assets/admin/css/style.css/wp-content/plugins/metadata-viewer/assets/admin/js/script.js/wp-content/plugins/metadata-viewer/assets/admin/js/highlight.jsmetadata-viewer/assets/admin/js/script.js?ver=metadata-viewer/assets/admin/js/highlight.js?ver=metadata-viewer/assets/admin/css/style.css?ver=