
Tools Engine – AIO Custom Fields Security & Risk Analysis
wordpress.org/plugins/tools-engineSimple and powerful tool to create custom fields for any post type in WordPress.
Is Tools Engine – AIO Custom Fields Safe to Use in 2026?
Generally Safe
Score 85/100Tools Engine – AIO Custom Fields has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tools-engine" v1.1 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by using prepared statements for all SQL queries and has a history devoid of known vulnerabilities, suggesting a commitment to security. However, significant concerns arise from its attack surface. A notable portion of its AJAX handlers (7 out of 46) and one REST API route lack proper authentication and permission checks, creating potential entry points for unauthorized actions. The presence of the `unserialize` function is also a cause for concern, as it can be a vector for remote code execution if not handled with extreme care and proper sanitization, although the static analysis did not report any specific exploitable flows. The bundled jQuery library is significantly outdated, posing a risk if any vulnerabilities are present in that specific version and are exploited by attackers.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API route
- Dangerous function (unserialize)
- Outdated bundled library (jQuery)
Tools Engine – AIO Custom Fields Security Vulnerabilities
Tools Engine – AIO Custom Fields Release Timeline
Tools Engine – AIO Custom Fields Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Tools Engine – AIO Custom Fields Attack Surface
AJAX Handlers 46
REST API Routes 1
Shortcodes 1
WordPress Hooks 49
Maintenance & Trust
Tools Engine – AIO Custom Fields Maintenance & Trust
Maintenance Signals
Community Trust
Tools Engine – AIO Custom Fields Alternatives
PostMeta Viewer – Custom Fields Inspector
postmeta-viewer
A powerful debugging tool for WordPress developers to inspect and analyze post meta (custom fields) across posts, pages, and custom post types.
MB Toolset Migration
mb-toolset-migration
Migrate custom fields from Toolset to Meta Box.
Advanced Custom Fields (ACF®)
advanced-custom-fields
ACF helps customize WordPress with powerful, professional and intuitive fields. Proudly powering over 2 million sites, WordPress developers love ACF.
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
Checkout Field Editor (Checkout Manager) for WooCommerce
woo-checkout-field-editor-pro
Checkout Field Editor (Checkout Manager) for WooCommerce – The best WooCommerce checkout manager plugin to manage WooCommerce checkout fields.
Tools Engine – AIO Custom Fields Developer Profile
23 plugins · 40K total installs
How We Detect Tools Engine – AIO Custom Fields
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tools-engine/app/blocks/tools-engine-block.jsHTML / DOM Fingerprints
smack_tools_engine_object/wp-json/tools-engine/fields/mydata[toolsengine