Custom fields frameworks render administrator-defined fields on post, term, user, and settings screens, store arbitrary meta, and expose AJAX endpoints for selecting posts, users, and terms, uploading and deleting files, and fetching oEmbeds. Meta Box – A Framework for Dynamic Websites version 5.15.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65699. The review focused on AJAX authorization and nonces, the file upload and delete flow, object-selection endpoints, meta storage and output escaping, and the [rwmb_meta] shortcode.

Name ofMeta Box – A Framework for Dynamic Websites
Version5.15.1
Active installations500,000+
DescriptionA developer toolkit to create custom meta boxes and custom fields in WordPress, with 40+ field types and support for custom post types, taxonomies, users, comments, and settings pages.
SecuritySuccessfully tested for:
SQL Injection (SQLi)
Cross-Site Scripting (XSS) – Stored and Reflected
Cross-Site Request Forgery (CSRF)
Authentication Vulnerabilities
Authentication Bypass Exploits
Privilege Escalation
Buffer Overflow
Denial-of-Service (DoS) vectors
Data Leakage Vulnerabilities
Insecure Dependency Usage
Remote Code Execution (RCE) Risks
Unauthorized File Access
Insufficient Injection Protection
Information Disclosure via Misconfigured Endpoints
CleanTalk CertificationProudly earned the “Plugin Security Certification” (PSC) from CleanTalk, indicating adherence to stringent security standards.
Additional InformationUse Meta Box with confidence backed by the “Plugin Security Certification” (PSC). When building public front-end forms, keep the front-end submission extension updated and restrict object-selection endpoints to the audiences that need them.
Plugin Security Certification by CleanTalk
Logo of the plugin

Join the community of developers who prioritize security. Highlight your plugin in the WordPress catalog.

PSC by Cleantalk

Key Features

Meta Box provides a developer-friendly framework for building custom meta boxes and custom fields in WordPress, with 40+ field types, support for posts, terms, users, comments and settings pages, cloneable and group fields, block editor and WooCommerce integrations, and helper functions plus a shortcode for displaying stored values.

Security Assurance

The CleanTalk Plugin Security Certification evaluation considered nonce and capability checks across the plugin’s AJAX endpoints (file deletion, post/user/term selection, and oEmbed), path confinement and ownership checks in the file-delete flow, parameterized database access, escaping of field attributes on output, and permission checks in the [rwmb_meta] shortcode before stored meta is returned.

The plugin has been successfully tested for:

✅ Information Leakage Vulnerabilities

✅ SQL Injection Vulnerabilities

✅ Cross-Site Scripting (XSS) Attacks

✅ Cross-Site Request Forgery (CSRF) Attacks

✅ Authentication and Authentication Bypass Vulnerabilities

✅ Privilege Escalation Vulnerabilities

✅ Buffer Overflow Vulnerabilities

✅ Denial-of-Service (DoS) Vulnerabilities

✅ Data Leakage Vulnerabilities

✅ Insecure Dependencies

✅ Code Execution Vulnerabilities

✅ File Unauthorized Access Vulnerabilities

✅ Insufficient Injection Protection

Conclusion

With PSC-2026-65699, Meta Box – A Framework for Dynamic Websites version 5.15.1 demonstrates a strong security baseline for custom-field storage, admin field rendering, file handling, and object-selection endpoints. The certification covers privileged AJAX actions, upload and deletion safety, output escaping, and shortcode permission checks. Site owners building public front-end forms should keep field-rendering extensions updated and confirm that object-selection endpoints are limited to the intended audience.

Note: The date and certification information may change over time. It is advisable to verify the latest details on the plugin developer’s website.

Plugin Security Certification (PSC-2026-65699): “Meta Box – A Framework for Dynamic Websites” – Version 5.15.1

Artyom Krugov

Cybersecurity Specialist with 4 years of hands-on experience in web application and WordPress security. Holder of the OSCP+ certification and author of 80+ publicly disclosed CVEs affecting WordPress plugins and themes. Specialized in vulnerability research, penetration testing, website incident response, malware removal, and security hardening of production environments. Experienced in identifying and validating high-impact vulnerabilities in WordPress plugins, themes, and custom web applications, as well as providing practical remediation guidance to improve overall security posture. Strong background in web application security, source code review, vulnerability assessment, exploit validation, and post-compromise recovery of infected websites.

Visit Author's Website

See all posts by krugov-artyom

Leave a Reply

Your email address will not be published. Required fields are marked *