ACF 5 Pro JSON Storage Security & Risk Analysis

wordpress.org/plugins/acf-5-pro-json-storage

Save ACF 5 Pro custom fields as JSON within this plugin, rather than inside your theme.

90 active installs v1.0.0 PHP + WP 3.5.0+ Updated Nov 14, 2015
acfprojsonlocationsavestorage
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ACF 5 Pro JSON Storage Safe to Use in 2026?

Generally Safe

Score 85/100

ACF 5 Pro JSON Storage has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The plugin 'acf-5-pro-json-storage' v1.0.0 demonstrates a strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in zero entry points and no unprotected ones. The code analysis also reveals no dangerous functions, SQL queries are exclusively handled with prepared statements, and all output is properly escaped. Furthermore, there are no file operations or external HTTP requests, and importantly, no nonce or capability checks are missing, indicating a deliberate design choice to avoid common plugin vulnerabilities. The absence of any recorded CVEs, past or present, further reinforces its secure track record. The taint analysis shows no flows with unsanitized paths, which is a significant positive indicator. The plugin's strengths lie in its minimal attack surface and apparent adherence to secure coding practices. However, the complete absence of capability checks across all potential (though currently zero) entry points, while not a direct vulnerability in this instance due to the lack of entry points, is a point of note. If functionality were to be added in the future, these checks would become crucial. Overall, the plugin appears very secure, with no immediately exploitable vulnerabilities identified.

Vulnerabilities
None known

ACF 5 Pro JSON Storage Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ACF 5 Pro JSON Storage Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

ACF 5 Pro JSON Storage Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filteracf/settings/save_jsonacf-5-json-storage.php:27
filteracf/settings/load_jsonacf-5-json-storage.php:39
Maintenance & Trust

ACF 5 Pro JSON Storage Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedNov 14, 2015
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs90
Developer Profile

ACF 5 Pro JSON Storage Developer Profile

craigsimps

3 plugins · 110 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ACF 5 Pro JSON Storage

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about ACF 5 Pro JSON Storage