
Rox Dynamic CPT Fields Engine Security & Risk Analysis
wordpress.org/plugins/rox-dynamic-cpt-fields-engineBuild Custom Post Types, Taxonomies, Custom Fields, Queries, and Listings from one unified interface.
Is Rox Dynamic CPT Fields Engine Safe to Use in 2026?
Generally Safe
Score 100/100Rox Dynamic CPT Fields Engine has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "rox-dynamic-cpt-fields-engine" plugin v1.0.0 exhibits a generally strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events with open attack surfaces significantly reduces its exploitability. Furthermore, the code demonstrates excellent security practices with 100% of SQL queries using prepared statements and a very high percentage (96%) of output being properly escaped. The presence of numerous nonce and capability checks also indicates a deliberate effort to implement access controls.
However, there is a single taint flow identified with an unsanitized path. While this flow is not classified as critical or high severity, it represents a potential area for concern as it indicates data originating from an untrusted source is not being sufficiently sanitized before being used in a way that could lead to unintended consequences, such as path traversal. The plugin's complete lack of a vulnerability history is a positive indicator, suggesting it has either been well-maintained or has not yet been a target for significant security research.
In conclusion, the plugin is well-developed from a security perspective, with minimal surface area and good implementation of security features. The lone unsanitized path is the primary area requiring attention. The absence of historical vulnerabilities is a strength, but users should remain vigilant for future updates and potential findings. The overall risk is considered low, but the identified taint flow warrants investigation and potential remediation.
Key Concerns
- Unsanitized path in taint flow
Rox Dynamic CPT Fields Engine Security Vulnerabilities
Rox Dynamic CPT Fields Engine Release Timeline
Rox Dynamic CPT Fields Engine Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Rox Dynamic CPT Fields Engine Attack Surface
WordPress Hooks 33
Maintenance & Trust
Rox Dynamic CPT Fields Engine Maintenance & Trust
Maintenance Signals
Community Trust
Rox Dynamic CPT Fields Engine Alternatives
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
Pods – Custom Content Types and Fields
pods
Pods is a framework for creating, managing, and deploying customized content types and fields for any project.
CubeWP Framework
cubewp-framework
CubeWP is an end-to-end dynamic content framework for WordPress to help you shrink time and cut cost of development up to 90%.
Custom post types, Custom Fields & more
custom-post-types
Custom Post Types, Custom Fields, Custom Taxonomies, Custom Templates, Custom Admin Pages, Custom Admin Notices. Directly from the WP dashboard.
LIQUID TOOLS – Custom Fields, CPT & Security
liquid-tools
Very simple tool to set up Custom Fields, Custom Post Types, Custom Taxonomies, and Security.
Rox Dynamic CPT Fields Engine Developer Profile
3 plugins · 0 total installs
How We Detect Rox Dynamic CPT Fields Engine
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rox-dynamic-cpt-fields-engine/assets/build/main-*.css/wp-content/plugins/rox-dynamic-cpt-fields-engine/assets/build/main-*.js/wp-content/plugins/rox-dynamic-cpt-fields-engine/assets/build/main-*.js/wp-content/plugins/rox-dynamic-cpt-fields-engine/assets/build/main-*.css?ver=/wp-content/plugins/rox-dynamic-cpt-fields-engine/assets/build/main-*.js?ver=HTML / DOM Fingerprints
type="module"window.rdcfeSettings/wp-json/rdcfe/v1/