shouldiuse.io

VERDICT

Should I use Meta Box?

The most powerful & comprehensive plugin to create, manage, show and connect dynamic data with forms and custom fields effortlessly on WordPress. - metabox.io

Depends. Buy if you're a WordPress developer or agency building structured, data-driven sites and will apply security updates promptly. Skip if you want a simple site — ACF or native custom fields is lighter.

Confidence

Medium. Based on 14 public sources. Trustpilot and laptop-review results were excluded — they cover a different Australian company, not the WordPress plugin.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support qualitySupport forums exist; no quality evidence
  • Security posture

Pricing

Free

Meta Box Lite

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
All-In-OnePaid bundle (price not shown in sources)

Best for

  • WordPress developers building custom post types
  • Agencies building directories and listing sites
  • Data-heavy editorial and OTA-style sites
  • Buyers comparing ACF who want a free core

Not for

  • Non-technical users wanting a simple blog or brochure site
  • Anyone who won't patch quickly — recurring CVE history
  • Buyers trying to shoehorn in CRM or database-app duty
  • One-page sites that just need a contact form

Gotchas - check before you buy

high

Auto-updates have broken sites with fatal errors — stage updates first

high

Several 2026 CVEs; falling behind on updates is risky

medium

Buying extensions individually stacks up; All-In-One bundle is the cheaper route

low

Free version historically lacked a UI — expect setup learning curve

Pros and cons

Pros

  • 4.8/5 average rating on reviews
  • Generous free Lite tier with UI builder
  • Feature-rich; repeatedly weighed against ACF, Pods, Carbon Fields
  • Detailed tutorials for complex builds, e.g.-style OTA
  • Dedicated security page and published fixes

Cons

  • Recurring CVEs: file deletion, path traversal, SQL injection, auth bypass
  • Code-first heritage; usable UI (Lite) came later
  • User reports: auto-update crashed custom fields with fatal errors
  • Many features sit in separate paid extensions

Sources & method

Analyzed 9/26/2026 - 14 sources - Repeated CVEs 2024–2026 (auth bypass, file deletion, path traversal, SQL injection); fixes have been published.

official x5review x5security x4
  • CVE-2024-43235 — authentication bypass, Authenticated bypass flaw in the Meta Box plugin.
  • Arbitrary file deletion (<= 5.11.1), Authenticated (Contributor+) arbitrary file deletion vulnerability.
  • CVE-2026-39468 — path traversal, Path traversal vulnerability in the Meta Box plugin.
  • Meta Box AIO vulnerabilities (2026), CVE-2026-14488 and CVE-2026-13355 disclosed in the AIO bundle.
  • Authenticated blind SQL injection, Blind SQL injection via a multi-meta component, per WPScan.

Key stats

  • Value for money: 4/5

    Rating

  • Free

    Starting price

  • 14

    Sources

  • Analyzed

  • Value for money: 4/5. Free Lite tier; lifetime deals have run
  • Ease of use: 3/5. Code-first roots; friendly UI arrived later
  • Feature depth: 5/5. Huge extension set; benchmarked against ACF
  • Support quality. Support forums exist; no quality evidence
  • Security posture: 2/5. Multiple CVEs 2024–2026; patches published
  • 4.8/5 WordPress.org rating Plugin review average
  • Yes Free tier Meta Box Lite, with UI builder
  • 8 Public CVEs listed WPScan/Wordfence, 2024–2026

Pricing

Meta Box Lite

Free

  • UI builder for custom fields
  • Core field functionality

All-In-One

Paid bundle (price not shown in sources)

  • Bundles the premium extensions

Security

Repeated CVEs 2024–2026 (auth bypass, file deletion, path traversal, SQL injection); fixes have been published.

  • CVE-2024-43235 — authentication bypassAuthenticated bypass flaw in the Meta Box plugin.⁸
  • Arbitrary file deletion (<= 5.11.1)Authenticated (Contributor+) arbitrary file deletion vulnerability.⁷
  • CVE-2026-39468 — path traversalPath traversal vulnerability in the Meta Box plugin.
  • Meta Box AIO vulnerabilities (2026)CVE-2026-14488 and CVE-2026-13355 disclosed in the AIO bundle.
  • Authenticated blind SQL injectionBlind SQL injection via a multi-meta component, per WPScan.14

What users say

Users rate it 4.8/5 on WordPress.org and constantly compare it with ACF, generally treating it as a strong, feature-rich alternative.

Full analysis

Based on 14 public sources. Trustpilot and laptop-review results were excluded — they cover a different Australian company, not the WordPress plugin.

Powerful WP custom-fields toolkit devs rate 4.8/5 — code-heavy roots, recurring CVEs. Overkill for simple sites.

Methodology

Based on 14 public sources. Trustpilot and laptop-review results were excluded — they cover a different Australian company, not the WordPress plugin.

Sources

  1. review
  2. official
  3. official
  4. official
  5. official
  6. security
  7. security
  8. security
  9. review
  10. review
  11. official
  12. review
  13. review
  14. security

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.