
ACF Booster Security & Risk Analysis
wordpress.org/plugins/acf-booster"ACF Booster" is a plugin which boosts up the functionality of Advanced Custom Fields.
Is ACF Booster Safe to Use in 2026?
Generally Safe
Score 85/100ACF Booster has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The ACF Booster v1.0 plugin presents a significant security risk due to its unprotected AJAX endpoints. While the plugin demonstrates good practices in other areas, such as using prepared statements for SQL queries and having no recorded vulnerabilities, the absence of authentication checks on two AJAX handlers creates a substantial attack surface. This means any unauthenticated user could potentially trigger these handlers, leading to unintended actions or data manipulation if the logic within these handlers is not robustly secured. The taint analysis also indicates flows with unsanitized paths, though currently assessed as not critical or high severity, this warrants attention in conjunction with the unprotected entry points. The lack of nonce checks and capability checks on these AJAX handlers further exacerbates the risk, leaving them vulnerable to CSRF attacks and privilege escalation if not properly handled. Overall, the plugin has strengths in its SQL handling and lack of historical vulnerabilities, but the unprotected AJAX endpoints are a critical weakness that needs immediate attention.
Key Concerns
- AJAX handlers without auth checks
- AJAX handlers without nonce checks
- AJAX handlers without capability checks
- Taint flows with unsanitized paths
- Low percentage of properly escaped output
ACF Booster Security Vulnerabilities
ACF Booster Code Analysis
Output Escaping
Data Flow Analysis
ACF Booster Attack Surface
AJAX Handlers 2
WordPress Hooks 10
Maintenance & Trust
ACF Booster Maintenance & Trust
Maintenance Signals
Community Trust
ACF Booster Alternatives
Advanced Custom Fields (ACF®)
advanced-custom-fields
ACF helps customize WordPress with powerful, professional and intuitive fields. Proudly powering over 2 million sites, WordPress developers love ACF.
ACF Content Analysis for Yoast SEO
acf-content-analysis-for-yoast-seo
WordPress plugin that adds the content of all ACF fields to the Yoast SEO score analysis.
Advanced Custom Fields: Extended
acf-extended
All-in-one enhancement suite that improves WordPress & Advanced Custom Fields.
Advanced Custom Fields: Font Awesome Field
advanced-custom-fields-font-awesome
Adds a new 'Font Awesome Icon' field to the popular Advanced Custom Fields plugin.
Table Field Add-on for ACF and SCF
advanced-custom-fields-table-field
A Table Field Add-on for the Advanced Custom Fields and Secure Custom Fields Plugin.
ACF Booster Developer Profile
20 plugins · 100 total installs
How We Detect ACF Booster
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/acf-booster/acf-counter.css/wp-content/plugins/acf-booster/js/acf-input-counter.js/wp-content/plugins/acf-booster/js/acf-word-check.js/wp-content/plugins/acf-booster/js/render-counter-setting.js/wp-content/plugins/acf-booster/js/render-ngword-setting.jsjs/acf-input-counter.jsjs/acf-word-check.jsjs/render-counter-setting.jsjs/render-ngword-setting.jsacf-input-counter.js?ver=acf-counter.css?ver=acf-word-check.js?ver=render-ngword-setting.js?ver=render-counter-setting.js?ver=HTML / DOM Fingerprints
name="ng-type-select"name="unique_ng_word"name="show_count"/wp-json/acf-booster/check_words