Metadata Viewer Security & Risk Analysis

wordpress.org/plugins/metadata-viewer

A plugin or theme developer can view metadata by this plugin easily.

300 active installs v2.1.1 PHP 7.4+ WP 6.0.0+ Updated Dec 24, 2025
custom-post-type-metameta-viewermetadatapost-metauser-meta
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Metadata Viewer Safe to Use in 2026?

Generally Safe

Score 100/100

Metadata Viewer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The metadata-viewer plugin version 2.1.1 exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the attack surface. Furthermore, the analysis indicates all SQL queries utilize prepared statements, and there are no file operations or external HTTP requests, which are common sources of vulnerabilities. The presence of capability checks is a positive sign for access control.

However, a significant concern arises from the output escaping analysis, where only 48% of outputs are properly escaped. This suggests a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is reflected in the output without adequate sanitization. The lack of nonce checks on any entry points, while limited by the small attack surface, could be a concern if new entry points were to be introduced in future versions.

The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the apparent lack of critical issues in the static analysis (no dangerous functions, no critical taint flows), suggests a well-maintained codebase for its current state. Despite the positive historical and static analysis indicators, the unescaped output remains the primary actionable security concern.

Key Concerns

  • Low output escaping percentage
Vulnerabilities
None known

Metadata Viewer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Metadata Viewer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
10 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

48% escaped21 total outputs
Attack Surface

Metadata Viewer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actioninitincludes\Assets.php:15
actionadmin_enqueue_scriptsincludes\Assets.php:18
actionplugins_loadedincludes\MetadataViewer.php:52
actionwoocommerce_flush_rewrite_rulesincludes\MetadataViewer.php:53
actioninitincludes\MetadataViewer.php:161
actionplugins_loadedincludes\MetadataViewer.php:162
actionadd_meta_boxesincludes\OrderMetaData.php:20
actionadd_meta_boxesincludes\PostMetaData.php:20
actionedit_user_profileincludes\UserMetaData.php:20
actionshow_user_profileincludes\UserMetaData.php:21
Maintenance & Trust

Metadata Viewer Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 24, 2025
PHP min version7.4
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs300
Developer Profile

Metadata Viewer Developer Profile

PluginizeLab

1 plugin · 300 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Metadata Viewer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/metadata-viewer/assets/admin/js/script.js/wp-content/plugins/metadata-viewer/assets/admin/js/highlight.js/wp-content/plugins/metadata-viewer/assets/admin/css/style.css
Script Paths
/wp-content/plugins/metadata-viewer/assets/admin/js/script.js/wp-content/plugins/metadata-viewer/assets/admin/js/highlight.js
Version Parameters
metadata-viewer/assets/admin/js/script.js?ver=metadata-viewer/assets/admin/js/highlight.js?ver=metadata-viewer/assets/admin/css/style.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Metadata Viewer