
ACF Block Generator Security & Risk Analysis
wordpress.org/plugins/acf-block-generatorQuickly create ACF gutenberg blocks using block.json.
Is ACF Block Generator Safe to Use in 2026?
Generally Safe
Score 92/100ACF Block Generator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'acf-block-generator' plugin version 1.1.8 exhibits a concerning security posture due to a significant number of unprotected entry points. All four identified AJAX handlers lack authentication checks, opening them up to potential unauthorized execution by unauthenticated users. While the plugin doesn't appear to have a history of known vulnerabilities, this absence of a track record should not be mistaken for inherent security. The static analysis reveals that all SQL queries are executed without prepared statements, posing a risk of SQL injection vulnerabilities. Furthermore, a substantial portion of output escaping is missing (only 46% properly escaped), increasing the likelihood of cross-site scripting (XSS) vulnerabilities. The presence of unsanitized paths in taint analysis flows is also a red flag, potentially leading to path traversal or arbitrary file read/write vulnerabilities, although the severity is not marked as critical or high. In conclusion, while the plugin has no recorded CVEs and includes nonce and capability checks on some functions, the unprotected AJAX handlers, raw SQL queries, and inadequate output escaping represent significant weaknesses that require immediate attention.
Key Concerns
- 4 AJAX handlers without auth checks
- 2 SQL queries, 0% using prepared statements
- 46% of outputs properly escaped
- 6 taint flows with unsanitized paths
ACF Block Generator Security Vulnerabilities
ACF Block Generator Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ACF Block Generator Attack Surface
AJAX Handlers 4
WordPress Hooks 28
Maintenance & Trust
ACF Block Generator Maintenance & Trust
Maintenance Signals
Community Trust
ACF Block Generator Alternatives
Spectra Gutenberg Blocks – Website Builder for the Block Editor
ultimate-addons-for-gutenberg
Power-up Gutenberg with advanced blocks for faster website creation. Build your WordPress website effortlessly using powerful building blocks!
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
kadence-blocks
20+ AI-powered Gutenberg Blocks with endless options, enabling top-notch efficiency for high-performance dynamic website creation.
Extendify
extendify
The best WordPress templates, pattern, and layout library with 1,000+ designs built for the Gutenberg block editor.
Page Builder: Pagelayer – Drag and Drop website builder
pagelayer
The most advanced frontend drag & drop page builder. Pagelayer is a light weight but extremely powerful Website Builder.
Page Builder Gutenberg Blocks – CoBlocks
coblocks
CoBlocks is a suite of page builder WordPress blocks for Gutenberg, with 10+ new blocks and a true page builder experience with rows and columns.
ACF Block Generator Developer Profile
1 plugin · 10 total installs
How We Detect ACF Block Generator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/acf-block-generator/appsero/src/Client.php/wp-content/plugins/acf-block-generator/appsero/src/class-insights.php/wp-content/plugins/acf-block-generator/appsero/src/class-updater.php/wp-content/plugins/acf-block-generator/appsero/src/views/notice.phpHTML / DOM Fingerprints
name='create_block_settings[block_name]'name='create_block_settings[block_description]'name='create_block_settings[block_icon]'name='create_block_settings[block_keywords]'name='create_block_settings[block_category]'name='create_block_settings[block_create_acf]'+6 morejQuery/wp-admin/admin-ajax.php