Simple Post Meta Manager Security & Risk Analysis

wordpress.org/plugins/simple-post-meta-manager

This plugin is for advanced WP editors / developers. It should increase the productivity when your post custom field's values are messed.

40 active installs v1.0.9 PHP + WP 3.1.0+ Updated Jan 9, 2016
post-metapost-meta-managerpost-meta-values
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEApr 9, 2025
Safety Verdict

Is Simple Post Meta Manager Safe to Use in 2026?

Use With Caution

Score 63/100

Simple Post Meta Manager has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Apr 9, 2025Updated 10yr ago
Risk Assessment

The "simple-post-meta-manager" v1.0.9 plugin presents a mixed security posture. While it demonstrates good practices in database interaction by exclusively using prepared statements for its SQL queries, significant concerns arise from its attack surface and output handling. The presence of one unprotected AJAX handler is a critical vulnerability, as it represents a direct entry point for malicious actors. Furthermore, the complete lack of proper output escaping on all identified output points (5 in total) indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the user's browser. The plugin also lacks nonce and capability checks, further exacerbating the risk associated with its unprotected AJAX endpoint.

The vulnerability history reveals a pattern of concerning issues, with one known medium-severity CVE related to Cross-Site Scripting, which remains unpatched. The fact that the last vulnerability was in 2025 suggests that the plugin may not be actively maintained or that past issues have not been fully addressed. The combination of an unprotected AJAX endpoint, rampant unescaped output, and a history of XSS vulnerabilities paints a picture of a plugin that requires immediate attention to secure its functionalities and protect users from potential attacks.

Key Concerns

  • Unprotected AJAX handler
  • No output escaping
  • No nonce checks
  • No capability checks
  • Unpatched medium CVE
Vulnerabilities
1

Simple Post Meta Manager Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-32556medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Simple Post Meta Manager <= 1.0.9 - Reflected Cross-Site Scripting

Apr 9, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Simple Post Meta Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
5
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

0% escaped5 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
simple_pmm_replace_meta_values_callback (simple-post-meta-manager.php:267)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Simple Post Meta Manager Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_simple_pmm_replace_meta_valuessimple-post-meta-manager.php:19
WordPress Hooks 2
actionadmin_menusimple-post-meta-manager.php:13
actionadmin_footersimple-post-meta-manager.php:18
Maintenance & Trust

Simple Post Meta Manager Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedJan 9, 2016
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs40
Developer Profile

Simple Post Meta Manager Developer Profile

Sandor Kovacs

5 plugins · 3K total installs

62
trust score
Avg Security Score
75/100
Avg Patch Time
3360 days
View full developer profile
Detection Fingerprints

How We Detect Simple Post Meta Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
simple-post-meta-manager/simple-post-meta-manager.php?ver=1.0.9

HTML / DOM Fingerprints

CSS Classes
nav-tab-active
Data Attributes
id='simple-sf'id='simple-pmm-meta-key'id='pmm-replace-value'id='pmm-new-meta-key-name'
JS Globals
window.confirm
FAQ

Frequently Asked Questions about Simple Post Meta Manager