Image

Beskrivelse

CMB2 er en del af udviklerens værktøjskasse til at bygge metabokse, brugerdefinerede felter eller formularer til WordPress der vil overgå dine vildeste fantasier. Håndter nemt metadata for indlæg, taksonomier, brugere, kommentarer eller opret brugerdefinerede indstillingssider.

CMB2 is a complete rewrite of Custom Metaboxes and Fields for WordPress. To get started, please follow the examples in the included example-functions.php file and have a look at the basic usage instructions.

You can see a list of available field types here.

Contribution

Development occurs on Github, and all contributions welcome. Please read the CONTRIBUTING doc for more details.

A complete list of all our awesome contributors found here: github.com/CMB2/CMB2/graphs/contributors

Features:

Translation

If you are looking to provide language translation files, Please do so via WordPress Plugin Translations.

Documentation

  • CMB2 documentation can be found at the CMB2 wiki on github. Also, If you’re into reading code and inline documentation, we tried to keep all functions and methods fully inline-documented.

3rd Party Resources

Custom Field Types

Other Helpful Resources

Links

View CHANGELOG

Known Issues

  • Metabox containing WYSIWYG editor cannot be moved or used in a repeatable way at this time (this is a TinyMCE issue).
  • Not all fields work well in a repeatable group.

Installation

If installing the plugin from wordpress.org:

  1. Upload the entire /CMB2 directory to the /wp-content/plugins/ directory.
  2. Activate CMB2 through the ‘Plugins’ menu in WordPress.
  3. Copy (and rename if desired) example-functions.php into to your theme or plugin’s directory.
  4. Edit to only include the fields you need and rename the functions.
  5. Profit.

If including the library in your plugin or theme:

  1. Place the CMB directory inside of your theme or plugin.
  2. Copy (and rename if desired) example-functions.php into a folder above the CMB directory OR copy the entirety of its contents to your theme’s functions.php file.
  3. Edit to only include the fields you need and rename the functions (CMB directory should be left unedited in order to easily update the library).
  4. Profit.

FAQ

FAQ’s usually end up in the github wiki.

Anmeldelser

Image
1. maj, 2025
Thank you for your hard work!One of the best plugin for developers. Simple and effective.
Image
3. april, 2024 1 svar
I love CMB2. I love hooking into functions and extending addons so fields update each other intelligently, while locking out non-admins to sections. Blocks are great, don’t get me wrong, and the extensions to make the, more hookable and meta-integrated is nice, but CMB2 gives you full and complete control, with API documented and dozens of add on plugins out there. Using FacetWP? We have an add on! Need to attach posts? We have an add on? Want to use Shadow Taxonomies to connect posts instead of attaching them and somehow manage to do so dynamically and speedily? Hey buddy. They’ve got you. The power is yours to command. Seeing even a version-matching-tested-up-to update makes me worry far less that this plugin will fall by the wayside. Up next? PHP 8 compat (I hope…)
Image
22. november, 2023
…easy to use, nice metaboxes for all post types
Læs alle 91 anmeldelser

Bidragsydere & udviklere

“CMB2” er open source-software. Følgende personer har bidraget til dette plugin.

Bidragsydere

“CMB2” er blevet oversat til 19 sprog. Tak til oversætterne for deres bidrag.

Oversæt “CMB2” til dit eget sprog.

Interesseret i udvikling?

Gennemse koden, tjek SVN repository, eller abonner på udviklerloggen via RSS.

Ændringslog

2.13.0

Enhancements

  • Added a rest_read_capability box property (also accepted as a field parameter) which declares who may read a box, or a single field on it, through the CMB2 REST API. The values read as plain English: false means no one, true means everyone (logged-out visitors included), 'box-capability' means holders of the box’s own capability parameter, and any other capability string means holders of that capability, e.g. 'edit_posts'. It cascades field box default the same way show_in_rest does, and the existing cmb2_api_get_box_permissions_check/cmb2_api_get_field_permissions_check filters still run afterward and have the final say. See REST API Read Permissions (#1563).
  • Added a site-wide cmb2_rest_enforce_options_page_read_permissions filter which aligns REST reads of options-page boxes with WordPress core’s settings/options convention, gating them behind the box capability rather than serving them publicly. It defaults to false, preserving CMB2’s current behavior, and is only consulted for boxes which have not declared a rest_read_capability. See REST API Read Permissions (#1563).
  • Added a dismissible admin notice for sites which register a REST-readable options-page box and have neither declared a rest_read_capability on it nor enabled the filter above. It links the REST API Read Permissions guide so those sites can pick the setting they want ahead of a later default change (#1563).
  • [Development] Added a SECURITY.md security policy and enabled GitHub private vulnerability reporting, giving researchers a private channel that does not depend on email delivery.

Bug Fixes

  • Aligned the oEmbed AJAX handler’s permission checks with CMB2’s other write paths: the handler now requires the caller to hold rights over the object the embed result is cached against (edit_post, edit_user, edit_comment, the taxonomy’s edit_terms, or, for an options-page target, the capability of the box that declared that option key) instead of relying on the nonce alone, and sanitizes the requested object type. Props Mutantgun (#1563).
  • Fixed CMB2_Base::maybe_hook_parameter() turning a caller’s default value into a declared box/field parameter. It passed the default through to prop(), which caches a truthy fallback on the object, so one request’s default persisted as a real parameter for every later call. Only a declared parameter is consulted now (#1563).
  • Sanitized the field_id input (with an isset() guard) and escaped the rel attribute in the oEmbed AJAX handler, addressing a reflected XSS vector flagged by WordPress Plugin Check. Props @thisismyurl (#1559).
  • Escaped the metabox ID output in the options-page form and the field ID output in the repeatable-field wrapper (id and data-selector attributes) with esc_attr(), resolving unescaped HTML attribute output flagged by WordPress Coding Standards. Props @thisismyurl (#1560).

2.12.0

Enhancements

  • Confirmed compatibility with PHP 8.2 and 8.3, and tested up to WordPress 7.0.
  • [Development] Migrated end-to-end testing from Cypress to Playwright and replaced Grunt with npm scripts for the asset build pipeline. (#1550).
  • [Development] Moved the local development and test environment to @wordpress/env (wp-env) on pinned ports, running both PHPUnit and Playwright through it. (#1554, #1558).
  • [Development] Replaced Travis CI with GitHub Actions, added a PHPCompatibility check (PHP 7.4+) and a PHPCS/WPCS lint gate, and overhauled install-wp-tests.sh for modern WordPress. (#1555).

Bug Fixes

  • Fixed a PHP 8.1+ deprecation when sanitizing an empty textarea-based field (passing null to wp_kses_post()). Props @baljindersingh88 (#1537).
  • Fixed row iterator value desync between the data attribute and jQuery data when reordering repeatable group rows. Props @angryaxi (#1518).
  • Fixed a PHP 8.3 ltrim() deprecation in the taxonomy field display.
  • Hardened against PHP 8.2+ dynamic property deprecations by widening #[AllowDynamicProperties] to the class roots.
  • Removed a focus-background rule on .cmb2-wrap inputs that caused unexpected input styling. Fixes #1556/wordpress.org/support/topic/weird-checkbox-behaviour-on-wp-7 (#1557).

2.11.0

Enhancements

  • Package updates.
  • Update WordPress Tested up to tag 6.1. Props @RubenMartins (#1477).
  • Add filters for setting object_id and mb_object_type and in do_scripts – Allows overriding by plugins/libs. (Added to support the new CMB2 WooCommerce HPOS Orders extension)
  • Added a cmb2_init_hooks hook when hookup is called.
  • Addressed some security concerns with the unserialization process for the stored serialized DateTime field values (text_datetime_timestamp_timezone field type only). (#1510)
  • [Development] Some build script improvements.
  • [Development] Added some PHPCS/WPCS config.
  • [Development] Added a phpcompatibility action. Props @jazzsequence (#1499, #1500).

Bug Fixes

  • Fix some line-height issues with dashicon buttons. Fixes [#1443](
  • Fix issue where image can be attached to wrong group after removing previous group. (#1473)
  • Fixes issue where Select/Deselect all does not trigger change JS DOM events. Fixes #1504.

2.10.1

Bug Fixes

  • Fix issue with date picker formatting. Fixes #1448.

2.10.0

Enhancements

  • Sanitize URLs, defaulting to https. Props @paulschreiber (#1413).
  • Establish Cypress E2E Testing. Props @markjaquith (#1437).
  • Updated the JS shiftRows functionality to be simpler, and fix issues with JS initialization. Fixes #1426 and #1431.
  • Updated various NPM dependencies for security issues.

Bug Fixes

  • Update to prevent deprecation notice:Required parameter $i follows optional parameter $args.... Props @carloswph (#1417).
  • Make each date field more resilient to various date/timestamp values passed in (from REST API).

2.9.0

Enhancements

  • Added cmb2_tab_group_tabs filter for adding arbitrary menu page urls to the cmb2 tabs, and move tab markup output to separate method, CMB2_Options_Hookup::options_page_tab_nav_output(). Fixes #1407.
  • Limit use of italic, including removing from field descriptions. Fixes #1404.
  • Add to list of valid image types from get_allowed_mime_types(), which makes SVGs more reliable when using the Safe SVG plugin. Fixes #1223.

Bug Fixes

  • Fixes PHP warnings on repeatable ColorPicker with an array as default. Props @rubengc (#1340).
  • Address PHP 7.4, compatibility issues with func_get_args(). Fixes #1389.
  • Better generated array key for cached fields, fixes issue where wrong field is found. Fixes #14053.
  • Fix issue with options-pages being changed to register on a hook priority of 5 instead of the default 10, causing some back-compatibility issues. Fixes #1410.

2.8.0

Enhancements

Bug Fixes

  • Ensure enqueue wp-color-picker is enqueued for color fields. Props @rubengc (#1339).
  • Fix empty name/id attributes on 'file_list' buttons. Props @pgroot91 (#1347).
  • Fix wysiwyg field type not working in a group, by ensuring scripts properly enqueued. Props @yoren (#1361).
  • Fix $object_id doc block types in helper-functions.php. Fixes #1365.
  • Fix Metabox toggles visually broken with WP 5.5.x. Fixes #1382.
  • Fix PHP Deprecated: Required parameter $field_id follows optional parameter $type, due to changes in PHP 8.0. Fixes #1396.
  • Fix PHP notice caused by deprecated_param method in PHP 7.4. Props @jonathanstegall (#1400).

2.7.0

Enhancements

  • Added support for sortable columns by default, with ability to disable with 'column' => array( 'disable_sortable' => true ). Props @RubenMartins (#1281).
  • New field type, 'taxonomy_select_hierarchical'. Fixes #751
  • New text, textarea and wysiwyg character counter options. For now, this feature is not available to wysiwyg field types within repeatable groups. Props @gyrus (#1276).
    • The new parameters:
      • 'char_counter' – Defaults to false, no counter. Set to true, or words to count words instead of characters.
      • 'char_max' – integer. When defined, counter shows remaining characters/words.
      • 'char_max_enforce' – boolean, default: false. Currently only applied (as maxlength attribute) to text and textarea fields which use 'characters' for counter.
    • You can also override the default text strings associated with these parameters:
      • 'words_left_text' – Default: “Words left”
      • 'words_text' – Default: “Words”
      • 'characters_left_text' – Default: “Characters left”
      • 'characters_text' – Default: “Characters”
      • 'characters_truncated_text' – Default: “Your text may be truncated.”
  • Update styling to be more compatible with WordPress 5.3. Props @galengidman (#1314)
  • Add a new box parameter, register_rest_field_cb, which when used allows overriding the way CMB2 handles the register_rest_field callbacks, and defining your own REST prefix for your fields. See this PR comment for more context.
  • Cleanup by renaming CMB2_hookup to CMB2_Hookup. Classes are case-insensitive, so this is a backwards-compatible change. Props @szepeviktor (#1330, #1328).
  • Validate composer.json for Travis CI. Props @szepeviktor (#1326).
  • Added LICENSE file to meet GitHub Community standards. Props @RubenMartins (#1316).
  • Add new "cmb2_display_class_{$fieldtype}" filter and 'display_class' field parameter to allow specifying the class to use to display the field (in admin columns, etc).
  • Update CMB2_Types::_id() to allow not appending the iterator attribute if a repeatable field.
  • Added CMB2_Utils::concat_attrs() test for nested arrays as data attributes.
  • Various updates per VIP feedback. Props @kevinlangleyjr, @mikeselander (#1255, #1257, #1259, #1261 #1262, and various direct commits. See #1260).

Bug Fixes

  • Fix some issues with Travis. Props @anhskohbo (#1220).
  • Javascript: Correctly pass the newly created row to the cmb2_add_row triggered event.
  • Various code-formatting and code documentation improvements. Props @tw2113.
  • Don’t exclude composer.json from the distribution. Props @johnbillion (#1225).
  • Ignore some more directories in the distribution package. Props @johnbillion (#1226).
  • Use CMB2_Field::get_rest_value() to get values for fields in the post REST API endpoints (#1284).
  • Fix issue where oEmbed fields’ live-preview would not work if the field was added within a group, along with some other similarly related issues. Fixes #1157.
  • Fix issue when using REST API for file and text_datetime_timestamp_timezone field types, the supporting field data was not provided (e.g. the file id for file field, and the utc value for the text_datetime_timestamp_timezone field). Fixes https://wordpress.org/support/topic/cmb2-rest-api-image-file-field-as-an-object/.
  • Escaping Improvements to File Base and File Fields. Props @tomjn (#1296, #1297).
  • Fix issue where repeatable CodeMirror textareas could not be clicked/draggged to highlight text. Props @JPry (#1300).
  • taxonomy_select_hierarchical now saves to the correct location, the term relationships table. Props @latheva (#1307).
  • Fix issue (#1158) where default REST API endpoints (e.g. /wp/v2/{post_type}) would show all boxes for all custom post types even though not registered to the post-type. Props @Mte90 (#1238).
  • Update and cull npm dependencis. Fixes #1308.
  • Fix some jshint issues.
  • Updated the WordPress embeds URL references.
  • Updates to account for WordPress 5.2 oEmbed changes.
  • Fix to ensure date picker fields can have a default value. Fixes #1245.
  • Added function_exists( 'add_action' ) check to bootstrap file to ensure compatibility with composer usage. Props @salcode (#1271, #1270)
  • Corrected link to facetwp-cmb2 in README.md. Props @marcelreschke (#1248).
  • Use get_user_locale() in admin area instead of get_locale(). Fixes #1267.
  • CMB2::is_box_type() now also checks for taxonomies if box is registered to “term” object type. This should fix some issues where CMB2 term meta was not showing up in REST API requests to the term endpoints.

2.6.0

Bug Fixes

  • Remove superfluous method definitions. Props @tnorthcutt (#1200).
  • Fix rest_value_cb registering of filter. Props @lipemat (#1212).
  • Do not trigger tinyMCE editor save for the activeEditor. Prevents cursor jump in Gutenberg. Fixes #1202
  • Fix issue where making a field repeatable would generate a Javascript error because of missing sortable library. Props @slaFFik (#1216).
  • Ensure value passed to CMB2_Utils::filter_empty from CMB2::save_group_field is always an array. (#1026)
  • Fix potential issue with test path location. Props @quasel (#463).

Enhancements

  • Updated PHPUnit version in composer.json. Props @slaFFik (#1204).
  • Package.json: fix the need of global (old) grunt. Props @slaFFik (#1206).
  • Add optional confirmation dialog to group field’s Remove button. Example documented in the example functions file. Props @slaFFik (#1208).
  • Add ‘id’ attribute on group field .postbox divs to ensure compatibility with scripts which expect ids there. Props @amans2k (#1108).
  • Make CMB2_Option properties accessible. (#1052)
  • New Before/After row hooks: 'cmb2_before_field_row', "cmb2_before_{$field_type}_field_row", "cmb2_after_{$field_type}_field_row", 'cmb2_after_field_row'. Props @rubengc (#953).
  • Introduce three new filters to filter field arguments: 'cmb2_field_defaults', 'cmb2_field_arguments_raw', 'cmb2_field_arguments'. Props @jrfnl (#588).

2.5.1

Bug Fixes

  • Fix issue when the core/editor object does not exist (is undefined), causing incompatibility issues with Yoast and likely others. Fixes #1197

2.5.0

Enhancements

  • Repeatable fields are now drag-sortable. Props @lipemat (#1142).
  • Update the sv_SE translation. Props @edvind (#370).
  • QA/PHPCS cleanup. Props @tw2113 (#1179).
  • Add optional 'mb_callback_args' CMB2 box property which allows defining the $callback_args passed into add_meta_box(). This allows using defining the new Gutenberg/block-editor compatibility parameters. Fixes #1191
  • Support any type of markup when customizing repeating group row. Props @lipemat (#1187).
  • Add cmb_init_pickers and cmb_init_code_editors Javascript events for allowing just-in-time configuration for pickers/editors.
  • Fix field descriptions color contrast ratio for better accessibility. h/t @rianrietveld. Fixes #1193.
  • Add CMB2_Field::get_rest_value() method for sending value through several filters ('cmb2_get_rest_value', "cmb2_get_rest_value_{$field_type}", "cmb2_get_rest_value_for_{$field_id}" ) before sending to REST request.

Bug Fixes

  • Fix the options page errors when using CMB2 in WordPress prior to 4.7. Props @manzoorwanijk (#1166).
  • Fix occasonal fatal errors that can occur by using callback functions directly vs call_user_func. Props @manzoorwanijk (#1177).
  • Fix issue where wysiwyg fields’ visual tab wouldn’t save content on Gutenberg/block-editor posts. Props @staurand (#1190 fixes #1156).
  • Fix issue when remove_default wouldn’t actually remove the default taxonomy metabox when box registration used an alternate box context. Props @lipemat (#1147).

2.4.2

Bug Fixes

  • Do not enqueue/register WordPress code editor JS if there are no textarea_code fields registered on the page. Fixes #1110.
  • Do not set repeated wysiwyg field values to string “false” when boolean false. Fixes #1138 (again!).

2.4.1

Bug Fixes

  • Do not set repeated field values to string “false” when boolean false. Fixes #1138.

2.4.0

Enhancements

  • Enable linking options pages via tabbed-navigation. Will output tabbed navigation for options-pages which share the same 'tab_group' CMB2 box property. This snippet demonstrates how to create a top-level menu options page with multiple submenu pages, each with the tabbed navigation. To specify a different tab title than the options-page title, set the 'tab_title' CMB2 box property. See #301, #627.
  • Complete the zh-CN translation. Props @uicestone (#1089).
  • Update the nl_NL translation. Props @tammohaannl (#1101).
  • Better display for white over transparent images (e.g. logos) by using a checkered background for images. (#1103)
  • Ability to disable the options autoload parameter via filter ("cmb2_should_autoload_{$options_key}") or via a box parameter for 'options-page' box registrations ('autoload' => false,). (#1093)
  • 'textarea_code' field type now uses CodeMirror that is used by WordPress (#1096). A field can opt-out to return to the previous behavior by specifying an 'options' parameter:
    ‘options’ => array( ‘disable_codemirror’ => true )
    As with the other javascript-enabled fields, the code-editor defaults can be overridden via a data-codeeditor attribute. E.g:

    `php
    

    ‘attributes’ => array(
    ‘data-codeeditor’ => json_encode( array(
    ‘codemirror’ => array(
    ‘mode’ => ‘css’,
    ),
    ) ),
    ),
    `

  • Improve/add comment info banners at top of CMB2 CSS files.
  • Added resetBoxes/resetBox Javascript methods for resetting CMB2 box forms.
  • Improved styles for fields in the new-term form.
  • New CMB2_Boxes methods for filtering instances of CMB2, CMB2_Boxes::get_by( $property, $optional_compare ) and CMB2_Boxes::filter_by( $property, $to_ignore = null ).

Bug Fixes

  • Fix the 'taxonomy_*' fields when used for term fields/meta. Save the value to term-meta.
  • Clear the CMB2 fields when a term is added. Fixes #794.
  • Repeated fields now use registered field defaults for values. Fixes #1137.
  • Fixed the formatting for deprecated messages in the log.
  • Prevent opening of media modal when clicking the file “Download” link. Fixes #1130.

2.3.0

Enhancements

Bug Fixes

  • Update for compatibility with PHP 7.2 (e.g. fixes Fatal error: Declaration of CMB2_Type_Colorpicker::render() must be compatible with CMB2_Type_Text::render($args = Array)...). (#1070, #1074, #1075).

Older versions

For the changelog of versions prior to 2.3.0, see CHANGELOG.md.