
Mj Term Meta Security & Risk Analysis
wordpress.org/plugins/mj-term-meta-boxThis plugin adds custom meta fields to
Is Mj Term Meta Safe to Use in 2026?
Generally Safe
Score 85/100Mj Term Meta has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mj-term-meta-box plugin v1.0.0 demonstrates a generally strong security posture with no known historical vulnerabilities or critical static analysis findings. The absence of dangerous functions, SQL injection vulnerabilities, and file operations is commendable. All observed output is properly escaped, and all SQL queries utilize prepared statements, indicating good development practices in these areas.
However, the static analysis does reveal two flows with unsanitized paths. While the taint analysis did not assign a critical or high severity to these, the presence of unsanitized paths is a potential concern. Furthermore, the plugin has zero nonce checks and zero capability checks. This complete lack of authorization and integrity checks on any potential entry points is a significant weakness. Given the absence of AJAX handlers, REST API routes, shortcodes, and cron events, the immediate attack surface is currently zero, which mitigates the risk of these missing checks *at this moment*. However, if future versions introduce any of these entry points without implementing proper authorization, it could lead to serious security vulnerabilities.
In conclusion, while the plugin currently benefits from a very limited attack surface and no known CVEs, the complete absence of nonce and capability checks represents a notable gap in its security architecture. The presence of unsanitized paths also warrants attention. The plugin's strength lies in its current lack of exploitable entry points and its use of prepared statements and output escaping. Its primary weakness is the potential for future vulnerabilities if entry points are added without corresponding security controls.
Key Concerns
- Unsanitized paths identified in taint analysis
- Missing nonce checks
- Missing capability checks
Mj Term Meta Security Vulnerabilities
Mj Term Meta Release Timeline
Mj Term Meta Code Analysis
Output Escaping
Data Flow Analysis
Mj Term Meta Attack Surface
WordPress Hooks 4
Maintenance & Trust
Mj Term Meta Maintenance & Trust
Maintenance Signals
Community Trust
Mj Term Meta Alternatives
Term Taxonomy Converter
term-taxonomy-converter
Copy or convert terms between taxonomies.
Term Menu Order
term-menu-order
Creates a 'menu_order' column to specify term order, allowing theme and plugin developers to sort term by menu order.
BulkPress – Export
bulkpress-export
Export taxonomies into formatted file compatible with BulkPress (Import) plugin.
Quick Bulk Tags Creator
quick-bulk-tags-creator
Easily add tags in bulk, and easily create a filter function to modifiy the values you insert
Select All Terms
select-all-terms
Adds buttons to select-all / deselect-all terms on taxonomies' metaboxes
Mj Term Meta Developer Profile
2 plugins · 10 total installs
How We Detect Mj Term Meta
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mj-term-meta-box/style.css/wp-content/plugins/mj-term-meta-box/script.js/wp-content/plugins/mj-term-meta-box/script.jsmj-term-meta-box/style.css?ver=mj-term-meta-box/script.js?ver=HTML / DOM Fingerprints
form-fielddescriptionfor="class_term_meta"id="class_term_meta"name="class_term_meta"