
Simple metadata Security & Risk Analysis
wordpress.org/plugins/simple-metadataThis plugin provides auto-generated metadata on the basis of default WP web-pages information.
Is Simple metadata Safe to Use in 2026?
Generally Safe
Score 85/100Simple metadata has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The simple-metadata plugin v1.6 presents a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities (CVEs) and a clean history, which suggests a generally stable and well-maintained codebase. The static analysis also indicates a good practice of implementing nonce checks and capability checks for many of its operations. Furthermore, there are no direct file operations or external HTTP requests, reducing the attack surface in those areas.
However, significant concerns arise from the taint analysis. With 4 out of 5 analyzed flows having unsanitized paths, and 2 of these identified as high severity, there is a notable risk of injection vulnerabilities. While the static analysis doesn't pinpoint the exact nature of these vulnerabilities, unsanitized paths in taint flows are a strong indicator of potential cross-site scripting (XSS) or other code execution risks if user-supplied data is not properly validated or escaped before being used in sensitive operations. The SQL query statistics, with 33% not using prepared statements, also indicate potential SQL injection vulnerabilities, although the taint analysis doesn't explicitly flag these as high severity.
In conclusion, while the plugin benefits from a lack of known vulnerabilities and a responsible approach to some security features like nonces and capabilities, the high number of unsanitized taint flows and the use of raw SQL queries are substantial weaknesses. These issues demand immediate attention to prevent potential security breaches, especially if the plugin handles user-provided data. The absence of recorded CVEs might be due to infrequent security auditing or that these vulnerabilities have not yet been discovered or publicly disclosed.
Key Concerns
- High severity taint flows with unsanitized paths
- Flows with unsanitized paths (non-critical)
- SQL queries not using prepared statements
- Bundled outdated library (Select2 v3.4.1)
Simple metadata Security Vulnerabilities
Simple metadata Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Simple metadata Attack Surface
WordPress Hooks 36
Maintenance & Trust
Simple metadata Maintenance & Trust
Maintenance Signals
Community Trust
Simple metadata Alternatives
Schema
schema
Get the next generation of Schema Structured Data to enhance your WordPress site presentation in Google search results.
WP Customer Reviews
wp-customer-reviews
Allows your visitors to leave business / product reviews. Testimonials are in Microdata / Microformat and may display star ratings in search results.
Review Schema – Review & Structure Data Schema Plugin
review-schema
WordPress Review Plugin with Schema adds Google Rich Snippets markup according to Schema.org guidelines to structure your website for SEO.
FAQ Schema For Pages And Posts
faq-schema-for-pages-and-posts
FAQ Schema For Pages And Posts by Krystian Szastok Founder of RobotZebra - a London based SEO agency, allows you to turn questions and answers on your …
Absolute Reviews
absolute-reviews
Add beautiful responsive and modern review boxes with valid JSON-LD schema to your posts with the “Advanced Reviews” plugin.
Simple metadata Developer Profile
9 plugins · 70 total installs
How We Detect Simple metadata
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-metadata/simple-metadata/style.css?ver=simple-metadata/script.js?ver=HTML / DOM Fingerprints
smd-posts-related-contentsmd-pages-related-contentsmd-frontpage-related-contentdata-field-idcustom_metadata_manager[simple_metadata_post][simple_metadata_page][simple_metadata_frontpage]