
Post Meta Controls Security & Risk Analysis
wordpress.org/plugins/post-meta-controlsUtilities to register, save and modify post meta data in the Gutenberg editor.
Is Post Meta Controls Safe to Use in 2026?
Generally Safe
Score 85/100Post Meta Controls has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'post-meta-controls' v1.4.1 exhibits a mixed security posture. On the positive side, the code analysis reveals good practices in several areas, including the absence of dangerous functions, all SQL queries utilizing prepared statements, and all identified output being properly escaped. Furthermore, there is a history of zero known vulnerabilities, which suggests a potentially well-maintained codebase or a lack of extensive public scrutiny regarding security flaws. The absence of file operations and external HTTP requests also reduces potential attack vectors.
However, a significant concern is the presence of one unprotected REST API route, which represents a direct entry point into the application without any authentication or permission checks. This is a critical oversight that could be exploited by unauthenticated users to interact with the plugin's functionality in unintended ways. The lack of nonce checks and capability checks on this entry point further exacerbates the risk, as it bypasses standard WordPress security mechanisms. While there are no critical taint flows or dangerous functions identified, the single unprotected REST API route represents a substantial security gap that needs immediate attention.
In conclusion, while 'post-meta-controls' v1.4.1 demonstrates strengths in data handling and output sanitization, the unprotected REST API endpoint is a glaring weakness. The history of no vulnerabilities is encouraging, but it does not negate the immediate risk posed by the identified exposed entry point. Users should be aware of this specific vulnerability and the potential for its exploitation.
Key Concerns
- Unprotected REST API route
- Missing capability checks on entry points
- Missing nonce checks on entry points
Post Meta Controls Security Vulnerabilities
Post Meta Controls Release Timeline
Post Meta Controls Code Analysis
Output Escaping
Post Meta Controls Attack Surface
REST API Routes 1
WordPress Hooks 5
Maintenance & Trust
Post Meta Controls Maintenance & Trust
Maintenance Signals
Community Trust
Post Meta Controls Alternatives
CMB2
cmb2
CMB2 is a metabox, custom fields, and forms library for WordPress that will blow your mind.
OptionTree
option-tree
Theme Options UI Builder for WordPress. A simple way to create & save Theme Options and Meta Boxes for free or premium themes.
Astra Bulk Edit
astra-bulk-edit
An easy-to-use plugin for the Astra theme that lets you edit Page Meta Settings for multiple pages/posts at once.
Custom Block Builder – Lazy Blocks
lazy-blocks
Easily create custom blocks and custom meta fields for Gutenberg without hard coding.
Pure Metafields
pure-metafields
Pure Metafields is very light weight plugin tused to create custom metabox for any post type like page, post and your custom post type support it.
Post Meta Controls Developer Profile
11 plugins · 3K total installs
How We Detect Post Meta Controls
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-meta-controls/dist/post-meta-controls.css/wp-content/plugins/post-meta-controls/dist/post-meta-controls.js/wp-content/plugins/post-meta-controls/dist/post-meta-controls-moment-locales.js/wp-content/plugins/post-meta-controls/dist/post-meta-controls.jspost-meta-controls/post-meta-controls.css?ver=post-meta-controls/post-meta-controls.js?ver=post-meta-controls/post-meta-controls-moment-locales.js?ver=HTML / DOM Fingerprints
data-setting-typePOSTMETACONTROLS/wp-json/post-meta-controls/v1/items