Pure Metafields Security & Risk Analysis

wordpress.org/plugins/pure-metafields

Pure Metafields is very light weight plugin tused to create custom metabox for any post type like page, post and your custom post type support it.

10K active installs v1.4.8 PHP 8.0+ WP 5.6+ Updated Jan 19, 2026
meta-fieldsmetaboxpage-metapost-meta
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Pure Metafields Safe to Use in 2026?

Generally Safe

Score 100/100

Pure Metafields has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The pure-metafields plugin v1.4.8 exhibits a strong security posture based on the provided static analysis. The complete absence of direct entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code demonstrates good security practices with 100% of SQL queries utilizing prepared statements and a very high percentage (98%) of output being properly escaped, which helps mitigate Cross-Site Scripting (XSS) vulnerabilities. The presence of nonce and capability checks, though limited in number, indicates an awareness of authentication and authorization mechanisms.

The taint analysis shows no identified flows with unsanitized paths, suggesting that data processing within the plugin is likely secure. The vulnerability history is also remarkably clean, with zero recorded CVEs. This lack of historical vulnerabilities, coupled with the robust static analysis findings, paints a picture of a well-developed and secure plugin. However, it's important to note that the absence of taint analysis flows might be due to the limited attack surface rather than inherently perfect sanitization across all potential pathways that might exist in more complex plugins. The use of a bundled library (Select2) warrants a minor check for known vulnerabilities in that specific component.

Key Concerns

  • Bundled library (Select2) may have unpatched vulnerabilities
Vulnerabilities
None known

Pure Metafields Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Pure Metafields Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
485 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

98% escaped493 total outputs
Attack Surface

Pure Metafields Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionplugins_loadedincludes\class-pure-metafields.php:136
actionadmin_enqueue_scriptsincludes\class-pure-metafields.php:151
actionadmin_enqueue_scriptsincludes\class-pure-metafields.php:152
actionenqueue_block_editor_assetsincludes\class-pure-metafields.php:153
actionload-post.phpincludes\class-pure-metafields.php:170
actionload-post.phpmetaboxes\class-metabox.php:17
actionload-post-new.phpmetaboxes\class-metabox.php:18
actionadmin_enqueue_scriptsmetaboxes\class-metabox.php:19
actionshow_user_profilemetaboxes\class-metabox.php:24
actionedit_user_profilemetaboxes\class-metabox.php:25
actionpersonal_options_updatemetaboxes\class-metabox.php:26
actionedit_user_profile_updatemetaboxes\class-metabox.php:27
filtermanage_users_columnsmetaboxes\class-metabox.php:28
filtermanage_users_custom_columnmetaboxes\class-metabox.php:29
actionadd_meta_boxesmetaboxes\class-metabox.php:61
actionsave_postmetaboxes\class-metabox.php:62
Maintenance & Trust

Pure Metafields Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 19, 2026
PHP min version8.0
Downloads65K

Community Trust

Rating86/100
Number of ratings6
Active installs10K
Developer Profile

Pure Metafields Developer Profile

Themepure

2 plugins · 11K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Pure Metafields

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pure-metafields/css/pure-metafields-admin.css/wp-content/plugins/pure-metafields/js/pure-metafields-admin.js/wp-content/plugins/pure-metafields/js/pure-metafields-admin-editor.js
Script Paths
/wp-content/plugins/pure-metafields/js/pure-metafields-admin.js/wp-content/plugins/pure-metafields/js/pure-metafields-admin-editor.js
Version Parameters
pure-metafields/css/pure-metafields-admin.css?ver=pure-metafields/js/pure-metafields-admin.js?ver=pure-metafields-admin-editor.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- pure-metafields -->
Data Attributes
data-plugin-name="pure-metafields"data-plugin-version="1.4.8"
JS Globals
window.tpmeta_meta_box
FAQ

Frequently Asked Questions about Pure Metafields