Post Meta Editor and Cleaner by RotiStudio Security & Risk Analysis

wordpress.org/plugins/rotistudio-post-meta-editor-cleaner

Post Meta bulk editor to delete unused data, overwrite values, run search and replace, and clean your database directly from the admin panel.

20 active installs v1.0.0 PHP 7.4+ WP 5.9+ Updated Mar 29, 2026
cleanupdatabaseeditoroptimizationpost-meta
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Post Meta Editor and Cleaner by RotiStudio Safe to Use in 2026?

Generally Safe

Score 100/100

Post Meta Editor and Cleaner by RotiStudio has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The rotistudio-post-meta-editor-cleaner v1.0.0 plugin exhibits a generally strong security posture. The static analysis reveals an absence of dangerous functions, secure SQL query practices with prepared statements, and complete output escaping. Furthermore, file operations and external HTTP requests are not utilized, and there is a lack of bundled libraries, which are all positive indicators of secure coding. The plugin also implements nonce and capability checks, albeit limited in number.

However, a concerning finding is a single flow with an unsanitized path identified during taint analysis. While not classified as critical or high severity, this indicates a potential weakness where user-supplied data might not be properly validated or sanitized before being used in a file path context. This could theoretically lead to directory traversal or other path manipulation vulnerabilities if exploited through the plugin's entry points. The absence of any past vulnerabilities is a positive trend, suggesting the developers are either diligent in their security practices or have not yet encountered security flaws. This indicates a need for further scrutiny of the identified unsanitized path flow to ensure it does not pose a real-world risk.

In conclusion, the plugin demonstrates good adherence to many security best practices, particularly in data handling and output sanitization. The presence of a single unsanitized path flow is the primary area of concern that warrants attention and mitigation. While the vulnerability history is clean, this does not negate the importance of addressing the identified static analysis findings. The plugin's limited attack surface and protective measures are strengths, but the taint analysis finding represents a weakness that could be exploited.

Key Concerns

  • Flow with unsanitized path
Vulnerabilities
None known

Post Meta Editor and Cleaner by RotiStudio Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Post Meta Editor and Cleaner by RotiStudio Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

Post Meta Editor and Cleaner by RotiStudio Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
5 prepared
Unescaped Output
0
154 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared5 total queries

Output Escaping

100% escaped154 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

4 flows1 with unsanitized paths
rspmeac_ajax_process_meta (admin/admin-core.php:343)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Post Meta Editor and Cleaner by RotiStudio Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_rspmeac_process_metaadmin/admin-core.php:423
WordPress Hooks 6
actionadmin_menuadmin/admin-core.php:122
actionload-admin_page_rspmeac-settingsadmin/admin-core.php:140
actionload-admin_page_rspmeac-helpadmin/admin-core.php:141
actionadmin_enqueue_scriptsadmin/admin-core.php:206
actionadmin_noticesadmin/admin-core.php:312
filterplugin_action_links_post-meta-eac-rotistudio/post-meta-eac-rotistudio.phpadmin/admin-core.php:479
Maintenance & Trust

Post Meta Editor and Cleaner by RotiStudio Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 29, 2026
PHP min version7.4
Downloads124

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Post Meta Editor and Cleaner by RotiStudio Developer Profile

Tamas Rottenbacher

2 plugins · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Post Meta Editor and Cleaner by RotiStudio

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rotistudio-post-meta-editor-cleaner/admin/css/admin-style.css/wp-content/plugins/rotistudio-post-meta-editor-cleaner/admin/js/admin-script.js
Script Paths
/wp-content/plugins/rotistudio-post-meta-editor-cleaner/admin/js/admin-script.js
Version Parameters
rotistudio-post-meta-editor-cleaner/admin/css/admin-style.css?ver=rotistudio-post-meta-editor-cleaner/admin/js/admin-script.js?ver=

HTML / DOM Fingerprints

JS Globals
rspmeacData
FAQ

Frequently Asked Questions about Post Meta Editor and Cleaner by RotiStudio