
ACF: Advanced Taxonomy Selector Security & Risk Analysis
wordpress.org/plugins/acf-advanced-taxonomy-selectorA field for Advanced Custom Fields which allows you to create a field where users can select terms or taxonommies flexibly.
Is ACF: Advanced Taxonomy Selector Safe to Use in 2026?
Generally Safe
Score 85/100ACF: Advanced Taxonomy Selector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of 'acf-advanced-taxonomy-selector' v3.1.0 reveals a seemingly secure plugin with no identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected by authentication checks. The absence of dangerous functions, file operations, external HTTP requests, and the use of prepared statements for all SQL queries are positive indicators of good development practices. Furthermore, the plugin's vulnerability history is clean, with no recorded CVEs, suggesting a stable and well-maintained codebase.
However, a significant concern arises from the output escaping analysis, where 0% of the 30 identified output points are properly escaped. This represents a critical weakness, as unsanitized output can lead to Cross-Site Scripting (XSS) vulnerabilities. Despite the lack of identified taint flows, the absence of output escaping creates a substantial attack surface for XSS. The complete lack of nonce and capability checks, while not directly flagged as exploitable due to the absence of entry points, indicates a potential for privilege escalation or unauthorized actions if new entry points are introduced or discovered in future versions without proper security considerations.
In conclusion, while the plugin exhibits strengths in its limited attack surface, lack of dangerous code, and clean vulnerability history, the universal failure to properly escape output is a major security flaw that significantly increases risk. Developers should prioritize addressing this output escaping issue to mitigate XSS vulnerabilities.
Key Concerns
- Output escaping: 0% properly escaped
- Nonce checks: 0
- Capability checks: 0
ACF: Advanced Taxonomy Selector Security Vulnerabilities
ACF: Advanced Taxonomy Selector Code Analysis
Output Escaping
ACF: Advanced Taxonomy Selector Attack Surface
WordPress Hooks 3
Maintenance & Trust
ACF: Advanced Taxonomy Selector Maintenance & Trust
Maintenance Signals
Community Trust
ACF: Advanced Taxonomy Selector Alternatives
Custom Fonts – Host Your Fonts Locally
custom-fonts
Custom Fonts is a powerful WordPress plugin that allows you to upload your own custom fonts or choose from a vast collection of Google Fonts, all host …
OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy.
host-webfonts-local
OMGF automagically caches the Google Fonts used by your theme/plugins locally. No configuration (or brains) required!
Fonts Plugin | Use Google Fonts, Adobe Fonts or Upload Fonts
olympus-google-fonts
The easiest to customize fonts in WordPress. Optimized for Speed. 1000+ font choices. Supports Google Fonts, Adobe Fonts and Upload Fonts.
Use Any Font | Custom Font Uploader
use-any-font
Upload custom fonts with custom font uploader. Auto converts to woff2 for better performance. Self-hosted, GDPR compliant, and easy custom font plugin
Disable and Remove Google Fonts | GDPR & DSGVO friendly
disable-remove-google-fonts
Improve frontend performance by disabling Google Fonts. GDPR and DSGVO friendly.
ACF: Advanced Taxonomy Selector Developer Profile
12 plugins · 7K total installs
How We Detect ACF: Advanced Taxonomy Selector
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/acf-advanced-taxonomy-selector/css/select2- ACF-ATF.css/wp-content/plugins/acf-advanced-taxonomy-selector/css/taxonomy-selector.css/wp-content/plugins/acf-advanced-taxonomy-selector/js/acf-advanced-taxonomy-selector.js/wp-content/plugins/acf-advanced-taxonomy-selector/js/select2.full.min.js/wp-content/plugins/acf-advanced-taxonomy-selector/js/taxonomy-selector.js/wp-content/plugins/acf-advanced-taxonomy-selector/js/acf-advanced-taxonomy-selector.js/wp-content/plugins/acf-advanced-taxonomy-selector/js/select2.full.min.js/wp-content/plugins/acf-advanced-taxonomy-selector/js/taxonomy-selector.jsacf-advanced-taxonomy-selector/css/select2-ACF-ATF.css?ver=acf-advanced-taxonomy-selector/css/taxonomy-selector.css?ver=acf-advanced-taxonomy-selector/js/acf-advanced-taxonomy-selector.js?ver=acf-advanced-taxonomy-selector/js/select2.full.min.js?ver=acf-advanced-taxonomy-selector/js/taxonomy-selector.js?ver=HTML / DOM Fingerprints
acf-advanced-taxonomy-selector-wrapacf-advanced-taxonomy-selector-fielddata-acf-taxonomy-selector-configacfAdvancedTaxonomySelector