Pods – Custom Content Types and Fields
by Scott Kingsley Clark · Uncategorized
Also makes 1 other plugin · 108K+ installs across the portfolio →
Pods is a framework for creating, managing, and deploying customized content types and fields for any project.
95 health vs 56 average across 16,378 Uncategorized plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Well tuned across the board
Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
120.6K
now · peak 182.1K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
7
releases in the last 12 months
3mo ago
latest release · v3.3.9
28
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 72% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “100K+”. Our estimate pins where the real number sits.
Modeled within the band wp.org reports; tightens as we track daily.
Install history · since 2015-03-16 · 1,496 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. The recent download trend is too spiky to read.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ kuseagentur2mo ago
Wir arbeiten inzwischen mit Divi 5 und Pods funktioniert hier sehr gut. Auch mit Divi 4 perfekt.
Read on wp.org ↗ - ★★★★★ Rainbow Forge5mo ago
Even the free version is more powerful than people understand. If you learn all of pods, you’re even able to bypass needing a premium plugin to display dynamic data. It’s a fantastic plugin and I hope that more people donate to the pods team to help improve their docs, as that is probably one of the main downsides.
Read on wp.org ↗ - ★★★★★ James Monroe6mo ago
Thank you for this amazing plugin and for making it so robust. Prefer to support a totally open-source community project like this when possible rather than commercial projects. Thanks also for adding block features and now block bindings!
Read on wp.org ↗ - ★★★★★ haas_ib8mo ago
Great! All in one free solution for custom post type, fields, taxonomies
Read on wp.org ↗ - ★★★★★ digitronic1.2y ago
Absolutely love PODS! I used it on quite a few sites, and the framework is as robust as it is ligthweight! Highly recommend id!
Read on wp.org ↗ - ★★★★★ pcarvalho1.4y ago
really powerful tool! love it!
Read on wp.org ↗ - ★★★★★ ldwd1.4y ago
Wow, I am impressed by this plugin! So easy to add custom post types with taxonomies, extend existing post types, and even add options pages. Very well done, you have one more happy user 🙂 Thank you!
Read on wp.org ↗ - ★★★★★ LilGames1.6y ago
At first glance, this plugin looks complicated. But after watching the main demonstration video on the Pods Framework website and then building my first “Pod”, which was a new Post type, HOLY COW does this ever open up so much customization possibilities! At first I started with the “Auto Template” and got something cool working with custom fields, but then I saw there are some “Pod” blocks. I turned off Auto-Template and created a couple more Pod templates for my custom Post type and that opened up so much in terms of putting in custom fields and content into more complex layouts! All without touching the PHP files! Very happy with this. I’ll be ditching “Theme Builders” from now on. To the developers of this great plugin: Keep it up!
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 3.3.9 Security: Resolve a XSS vulnerability in the Pods UI forms in the admin area. Props to Bonds through Patchstack for responsibly reporting this. (@sc0ttkclark) 3.3.9
- — Version 3.3.8 Feature: Reuse the same UI that Repeatable Fields use for the Relationship fields using “List View” list items. The UI is now consistent and Pods 3.4 will include the same UI treatment for the File fields. (@sc0ttkclark) 3.3.8
- — Version 3.3.7 Fixed: Resolve issues using WP_Filesystem to check session paths before starting a session. (@sc0ttkclark) Fixed: Prevent deprecated notices with non-strings being passed to strpos . (@sc0ttkclark) 3.3.7
- — Version 3.3.6 Fixed: Resolve a fatal error with WP_Filesystem usage. (@sc0ttkclark) 3.3.6
- — Version 3.3.5 Minimum Requirements Notice: Pods 3.4 coming in 2026 will require new minimum versions of WordPress 6.8+, PHP 8.0+, and MySQL 5.7+ Feature: Added support for showing fields as “Read Only” in forms when a user does not ha 3.3.5
- — Version 3.3.4 Feature: Official support for DID did:plc:e3rm6t7cspgpzaf47kn3nnsl for optional installation via DID using the FAIR plugin. (@sc0ttkclark) Fix: Prevent duplicates in Pods::field() and Pods::display() for simple relations 3.3.4
Known vulnerabilities
via Wordfence Intelligence17 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- High · 7.2 Pods – Custom Content Types and Fields <= 3.3.8 - Unauthenticated Stored Cross-Site Scripting ↗2026-06-15 CVE-2026-54191 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.3.8 Patched in 3.3.9
- Medium · 4.4 Pods – Custom Content Types and Fields <= 3.2.8.1 - Authenticated (Admin+) Stored Cross-Site Scripting ↗2025-03-02 CVE-2025-1446 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.8.1 Patched in 3.2.8.2
- Medium · 4.4 Pods – Custom Content Types and Fields <= 3.2.8 - Authenticated (Admin+) Stored Cross-Site Scripting ↗2024-12-16 CVE-2024-11849 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.8 Patched in 3.2.8.1
- 2024-10-15 CVE-2024-9883 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.7 Patched in 3.2.7.1
- 2024-05-09 CVE-2024-3956 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.1 Patched in 3.2.1.1
- High · 8.8 Pods - Custom Content Types and Fields - Authenticated (Contributor+) SQL Injection via Shortcode ↗2024-03-28 CVE-2023-6967 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 2.7.31 Patched in 2.7.31.2
- High · 8.8 Pods - Custom Content Types and Fields - Authenticated (Contributor+) Remote Code Execution ↗2024-03-28 CVE-2023-6999 Improper Neutralization of Special Elements used in a Command ('Command Injection') Affects < 2.7.31 Patched in 2.7.31.2
- Medium · 5.5 Pods – Custom Content Types and Fields <= 2.7.28 - Authenticated (Admin+) Cross-Site Scripting ↗2021-08-06 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.7.28 Patched in 2.7.29
- 2021-01-15 CVE-2021-24338 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects 2.4.4.1 - 2.7.27 Patched in 2.7.27
- 2021-01-15 CVE-2021-24339 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects 2.4.4.2 - 2.7.26 Patched in 2.7.27
- 2015-03-16 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 2.5.1.2 Patched in 2.5.1.2
- Medium · 6.1 Pods <= 2.4.3 - Cross-Site Scripting ↗2015-01-12 CVE-2014-7956 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.4.3 Patched in 2.5
- Critical · 9.6 Pods <= 2.4.3 - Multiple Cross-Site Request Forgery ↗
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0.1
Languages
via translate.wordpress.orgTranslated into 76 languages, 6 at 90% or more
Plus 52 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
No tier crossings observed yet.
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Meta Box 500K+ installs · 4.8★ · 3 shared tags A -
CubeWP Framework 4K+ installs · 4.3★ · 3 shared tags A -
Custom post types, Custom Fields & more 3K+ installs · 4.5★ · 3 shared tags B
-
LIQUID TOOLS – Custom Fields, CPT & Security 100+ installs · 3.6★ · 3 shared tags B -
Custom Post Type UI 1M+ installs · 4.6★ · 2 shared tags A - S Sydney Toolbox 50K+ installs · 3.0★ · 2 shared tags D
Embed this report card
Drop a live Pulse card for Pods – Custom Content Types and Fields into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/pods" width="480" height="300" style="border:0" loading="lazy" title="Pods – Custom Content Types and Fields — Plugin Pulse"></iframe> Pods – Custom Content Types and Fields: 100K+ active installs, 4.8★ (418 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/pods