
Advanced Custom Fields: Button Field Security & Risk Analysis
wordpress.org/plugins/acf-buttonGenerates a button to an external url or an internal post type. Integrates with custom post types too.
Is Advanced Custom Fields: Button Field Safe to Use in 2026?
Generally Safe
Score 85/100Advanced Custom Fields: Button Field has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "acf-button" v1.7.3 plugin exhibits an excellent security posture based on the provided static analysis results. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code demonstrates robust security practices, with no dangerous functions, all SQL queries using prepared statements, and 100% of output properly escaped. The lack of file operations, external HTTP requests, and vulnerability history further bolster its security profile.
However, the analysis did reveal some areas for potential improvement. Specifically, the complete absence of nonce checks and capability checks is a concern, even though no direct entry points were identified in this specific scan. This could leave the plugin vulnerable if new entry points are introduced or if existing ones are inadvertently exposed in future versions. While the vulnerability history is clean, the lack of any security checks like nonces or capability checks in the current code presents a hypothetical risk that should be addressed proactively.
Overall, "acf-button" v1.7.3 appears to be a very secure plugin with no known vulnerabilities and strong adherence to secure coding principles in its current state. The main weakness lies in the lack of fundamental security checks like nonces and capability checks, which, while not directly exploitable in this scan, represent a potential oversight that could lead to issues if the plugin's attack surface were to expand or change.
Key Concerns
- No nonce checks found
- No capability checks found
Advanced Custom Fields: Button Field Security Vulnerabilities
Advanced Custom Fields: Button Field Release Timeline
Advanced Custom Fields: Button Field Code Analysis
Output Escaping
Advanced Custom Fields: Button Field Attack Surface
WordPress Hooks 1
Maintenance & Trust
Advanced Custom Fields: Button Field Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Custom Fields: Button Field Alternatives
Custom Post Type Permalinks
custom-post-type-permalinks
Edit the permalink of custom post type.
Remove CPT base
remove-cpt-base
Remove custom post type base slug from url
Simple Post Type Permalinks
simple-post-type-permalinks
Easy to change Permalink of custom post type.
Custom Share Buttons with Floating Sidebar
custom-share-buttons-with-floating-sidebar
Share buttons with extra features to sharing your website posts/pages on Facebook, Twitter, Instagram, Whatsapp, Pinterest etc.
CubeWP Framework
cubewp-framework
CubeWP is an end-to-end dynamic content framework for WordPress to help you shrink time and cut cost of development up to 90%.
Advanced Custom Fields: Button Field Developer Profile
4 plugins · 330 total installs
How We Detect Advanced Custom Fields: Button Field
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/acf-button/css/acf-button.css/wp-content/plugins/acf-button/js/acf-button.js/wp-content/plugins/acf-button/js/acf-button.jsacf-button/css/acf-button.css?ver=acf-button/js/acf-button.js?ver=HTML / DOM Fingerprints
acf-button-field<!-- acf-button -->data-allow-advanceddata-default-textdata-default-targetdata-default-colordata-default-sizedata-default-style+1 moreacf.fields.button[acf_button