
ACF Advanced Search Security & Risk Analysis
wordpress.org/plugins/acf-advanced-searchAdvanced search for the Advanced Custom Fields plugin (Free & Pro).
Is ACF Advanced Search Safe to Use in 2026?
Generally Safe
Score 85/100ACF Advanced Search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'acf-advanced-search' plugin version 1.2.1 demonstrates some good security practices, particularly in its handling of SQL queries, which are all prepared statements, and the absence of file operations or external HTTP requests. Furthermore, its limited attack surface of only one shortcode and no identified AJAX handlers or REST API routes is a positive sign. The plugin also has no known past or present CVEs, suggesting a historically stable security record.
However, there are significant concerns. The complete lack of nonce checks and capability checks is a major weakness. This means that any entry point, even a simple shortcode, could be invoked by an unauthenticated or unauthorized user. The taint analysis revealing flows with unsanitized paths, although not classified as critical or high severity, still indicates a potential for issues if these paths are exploited. The most alarming finding is the extremely low percentage of properly escaped output (13%). This strongly suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities across numerous output points within the plugin.
In conclusion, while the plugin avoids some common pitfalls like raw SQL and external requests, the absence of essential security checks for nonces and capabilities, combined with widespread output escaping deficiencies, creates a substantial security risk. The vulnerability history is a positive, but the code analysis reveals immediate and serious potential for compromise, particularly through XSS attacks.
Key Concerns
- Output escaping significantly deficient (13% proper)
- Missing nonce checks on all entry points
- Missing capability checks on all entry points
- Taint analysis shows unsanitized paths
ACF Advanced Search Security Vulnerabilities
ACF Advanced Search Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ACF Advanced Search Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
ACF Advanced Search Maintenance & Trust
Maintenance Signals
Community Trust
ACF Advanced Search Alternatives
ACF Content Analysis for Yoast SEO
acf-content-analysis-for-yoast-seo
WordPress plugin that adds the content of all ACF fields to the Yoast SEO score analysis.
Advanced Custom Fields: Font Awesome Field
advanced-custom-fields-font-awesome
Adds a new 'Font Awesome Icon' field to the popular Advanced Custom Fields plugin.
Table Field Add-on for ACF and SCF
advanced-custom-fields-table-field
A Table Field Add-on for the Advanced Custom Fields and Secure Custom Fields Plugin.
ACF: Better Search
acf-better-search
This plugin adds to default WordPress search engine the ability to search by content from selected fields of Advanced Custom Fields plugin.
WP All Import – Import Add-On for ACF
csv-xml-import-for-acf
Drag & drop to import any CSV, Excel, XML, or Google Sheets file into Advanced Custom Fields. Supports repeaters, flexible content, galleries, and …
ACF Advanced Search Developer Profile
3 plugins · 90 total installs
How We Detect ACF Advanced Search
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/acf-advanced-search/assets/css/styles.css/wp-content/plugins/acf-advanced-search/assets/js/scripts.js/wp-content/plugins/acf-advanced-search/assets/js/scripts.jsacf-advanced-search/assets/css/styles.css?ver=acf-advanced-search/assets/js/scripts.js?ver=HTML / DOM Fingerprints
datarowcol-sm-6col-md-4col-lg-3termvaluedata-field_typedata-field_name[displayACFfields]