
Post Meta Manager Security & Risk Analysis
wordpress.org/plugins/post-meta-managerA simple utility plugin for changing or deleting post or user meta (custom fields) keys in bulk.
Is Post Meta Manager Safe to Use in 2026?
Generally Safe
Score 85/100Post Meta Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "post-meta-manager" v1.0.4 exhibits a generally good security posture based on the provided static analysis. It has a small attack surface consisting solely of two AJAX handlers, both of which appear to have authentication checks based on the 'Unprotected: 0' figure. The absence of REST API routes, shortcodes, and cron events further limits potential entry points. Crucially, the taint analysis found no critical or high severity flows, and there are no known CVEs associated with this plugin, indicating a history of responsible development and maintenance. The presence of nonce checks and a moderate percentage of SQL queries using prepared statements are positive indicators.
However, there are areas for improvement. The fact that none of the AJAX handlers or REST API routes have capability checks (indicated by 'Capability checks: 0') is a significant concern. While nonce checks can prevent basic CSRF attacks, they do not verify if the user performing the action has the necessary permissions. Additionally, 50% of output escaping is not ideal; unescaped output can lead to Cross-Site Scripting (XSS) vulnerabilities. The presence of SQL queries without prepared statements, even if a minority, also presents a risk of SQL injection.
In conclusion, "post-meta-manager" v1.0.4 demonstrates a solid foundation with a small attack surface and no known vulnerabilities. The primary weaknesses lie in the lack of capability checks on its entry points and the partial implementation of output escaping. Addressing these would significantly enhance the plugin's security.
Key Concerns
- AJAX handlers missing capability checks
- 50% of outputs not properly escaped
- SQL queries without prepared statements (non-critical)
Post Meta Manager Security Vulnerabilities
Post Meta Manager Release Timeline
Post Meta Manager Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Post Meta Manager Attack Surface
AJAX Handlers 2
WordPress Hooks 3
Maintenance & Trust
Post Meta Manager Maintenance & Trust
Maintenance Signals
Community Trust
Post Meta Manager Alternatives
WP-Admin Search Post Meta
wp-admin-search-meta
Search WordPress admin posts by custom fields (post meta) directly from the default search.
JSM Show Post Metadata
jsm-show-post-meta
Show post metadata (aka custom fields) in a metabox when editing posts / pages - a great tool for debugging issues with post metadata.
JSM Show User Metadata
jsm-show-user-meta
Show user metadata in a metabox when editing users - a great tool for debugging issues with user metadata.
Ultimate Fields
ultimate-fields
Easy and powerful custom fields management: Post Meta, Options Pages, Repeaters and many field types!
Custom Metadata Manager
custom-metadata
An easy way to add custom fields to your object types (post, pages, custom post types, users)
Post Meta Manager Developer Profile
20 plugins · 2K total installs
How We Detect Post Meta Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-meta-manager/lib/css/pmm.admin.min.css/wp-content/plugins/post-meta-manager/lib/js/pmm.ajax.min.js/wp-content/plugins/post-meta-manager/lib/js/pmm.ajax.min.jspost-meta-manager/lib/css/pmm.admin.min.css?ver=post-meta-manager/lib/js/pmm.ajax.min.js?ver=HTML / DOM Fingerprints
pmmAjaxData