
ACF: Better Search Security & Risk Analysis
wordpress.org/plugins/acf-better-searchThis plugin adds to default WordPress search engine the ability to search by content from selected fields of Advanced Custom Fields plugin.
Is ACF: Better Search Safe to Use in 2026?
Generally Safe
Score 99/100ACF: Better Search has a strong security track record. Known vulnerabilities have been patched promptly.
The ACF Better Search plugin, version 4.4.1, exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, and external HTTP requests is commendable. Importantly, all SQL queries are prepared, and all detected outputs are properly escaped, significantly reducing the risk of common web vulnerabilities like SQL injection and XSS. The presence of nonce checks also indicates an awareness of security best practices.
However, the taint analysis reveals a potential area of concern: 3 flows with unsanitized paths were identified. While no critical or high severity issues were flagged in the taint analysis, the presence of unsanitized paths, even if not immediately exploitable in this version, warrants attention as it could indicate potential weaknesses in how the plugin handles file or path operations under different conditions or future updates.
The vulnerability history shows a single past CVE, a Cross-Site Request Forgery, which was patched. The fact that there are no currently unpatched CVEs is a positive sign. The plugin has a history of addressing its vulnerabilities, which is a good indicator of maintenance. Overall, ACF Better Search v4.4.1 appears to be a secure plugin with good coding practices, but the identified unsanitized paths in the taint analysis should be monitored for potential future risks.
Key Concerns
- Flows with unsanitized paths detected
ACF: Better Search Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
ACF Better Search <= 3.3.0 - Cross-Site Request Forgery
ACF: Better Search Code Analysis
Output Escaping
Data Flow Analysis
ACF: Better Search Attack Surface
WordPress Hooks 13
Maintenance & Trust
ACF: Better Search Maintenance & Trust
Maintenance Signals
Community Trust
ACF: Better Search Alternatives
WP Fast Total Search – The Power of Indexed Search
fulltext-search
Extends the default fulltext search with relevance, jet speed and ability to search any posts, metadata, taxonomy, shortcode content and more data.
Relevanssi – A Better Search
relevanssi
Relevanssi replaces the default search with a partial-match search that sorts results by relevance. It also indexes comments and shortcode content.
Ajax Search Lite – Live Search & Filter
ajax-search-lite
The Best Ajax Live Search and Filter for WordPress. Live suggestions, Custom Post types, Custom fields, Categories, WooCommerce & Elementor support
Better Search – Relevant search results for WordPress
better-search
Better Search replaces the default WordPress search with a better search engine that gives contextual results sorted by relevance.
SearchIQ – The Search Solution
searchiq
Our FREE plugin makes your website’s search fast and more relevant. searchIQ helps you to manage content more effectively with real-time analytics.
ACF: Better Search Developer Profile
3 plugins · 541K total installs
How We Detect ACF: Better Search
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/acf-better-search/assets/build/css/styles.css/wp-content/plugins/acf-better-search/assets/build/js/scripts.js/wp-content/plugins/acf-better-search/assets/build/js/scripts.jsacf-better-search/assets/build/css/styles.css?ver=acf-better-search/assets/build/js/scripts.js?ver=