Custom fields frameworks render administrator-defined fields on post, term, user, and settings screens, store arbitrary meta, and expose AJAX endpoints for selecting posts, users, and terms, uploading and deleting files, and fetching oEmbeds. Meta Box – A Framework for Dynamic Websites version 5.15.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65699. The review focused on AJAX authorization and nonces, the file upload and delete flow, object-selection endpoints, meta storage and output escaping, and the [rwmb_meta] shortcode.
| Name of | Meta Box – A Framework for Dynamic Websites |
| Version | 5.15.1 |
| Active installations | 500,000+ |
| Description | A developer toolkit to create custom meta boxes and custom fields in WordPress, with 40+ field types and support for custom post types, taxonomies, users, comments, and settings pages. |
| Security | Successfully tested for: SQL Injection (SQLi) Cross-Site Scripting (XSS) – Stored and Reflected Cross-Site Request Forgery (CSRF) Authentication Vulnerabilities Authentication Bypass Exploits Privilege Escalation Buffer Overflow Denial-of-Service (DoS) vectors Data Leakage Vulnerabilities Insecure Dependency Usage Remote Code Execution (RCE) Risks Unauthorized File Access Insufficient Injection Protection Information Disclosure via Misconfigured Endpoints |
| CleanTalk Certification | Proudly earned the “Plugin Security Certification” (PSC) from CleanTalk, indicating adherence to stringent security standards. |
| Additional Information | Use Meta Box with confidence backed by the “Plugin Security Certification” (PSC). When building public front-end forms, keep the front-end submission extension updated and restrict object-selection endpoints to the audiences that need them. |
| Plugin Security Certification by CleanTalk | ![]() |
| Logo of the plugin |
PSC by CleantalkJoin the community of developers who prioritize security. Highlight your plugin in the WordPress catalog.
Key Features
Meta Box provides a developer-friendly framework for building custom meta boxes and custom fields in WordPress, with 40+ field types, support for posts, terms, users, comments and settings pages, cloneable and group fields, block editor and WooCommerce integrations, and helper functions plus a shortcode for displaying stored values.
Security Assurance
The CleanTalk Plugin Security Certification evaluation considered nonce and capability checks across the plugin’s AJAX endpoints (file deletion, post/user/term selection, and oEmbed), path confinement and ownership checks in the file-delete flow, parameterized database access, escaping of field attributes on output, and permission checks in the [rwmb_meta] shortcode before stored meta is returned.
The plugin has been successfully tested for:
✅ Information Leakage Vulnerabilities
✅ SQL Injection Vulnerabilities
✅ Cross-Site Scripting (XSS) Attacks
✅ Cross-Site Request Forgery (CSRF) Attacks
✅ Authentication and Authentication Bypass Vulnerabilities
✅ Privilege Escalation Vulnerabilities
✅ Buffer Overflow Vulnerabilities
✅ Denial-of-Service (DoS) Vulnerabilities
✅ Data Leakage Vulnerabilities
✅ Insecure Dependencies
✅ Code Execution Vulnerabilities
✅ File Unauthorized Access Vulnerabilities
✅ Insufficient Injection Protection
Conclusion
With PSC-2026-65699, Meta Box – A Framework for Dynamic Websites version 5.15.1 demonstrates a strong security baseline for custom-field storage, admin field rendering, file handling, and object-selection endpoints. The certification covers privileged AJAX actions, upload and deletion safety, output escaping, and shortcode permission checks. Site owners building public front-end forms should keep field-rendering extensions updated and confirm that object-selection endpoints are limited to the intended audience.
Note: The date and certification information may change over time. It is advisable to verify the latest details on the plugin developer’s website.
