Date & Time Picker for Advanced Custom Fields Security & Risk Analysis

wordpress.org/plugins/acf-date-time-picker

Date & Time Picker field for Advanced Custom Fields 4 and 5.

300 active installs v1.1.4 PHP + WP 3.5+ Updated May 3, 2016
acfadvanced-custom-fieldscustom-fielddatepickertimepicker
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Date & Time Picker for Advanced Custom Fields Safe to Use in 2026?

Generally Safe

Score 85/100

Date & Time Picker for Advanced Custom Fields has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The 'acf-date-time-picker' plugin version 1.1.4 exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code demonstrates good practices by using prepared statements for all SQL queries and a high percentage of properly escaped output, minimizing risks of SQL injection and Cross-Site Scripting (XSS). The lack of file operations and external HTTP requests further contributes to a reduced threat landscape.

However, a notable concern is the complete absence of nonce checks and capability checks across all identified entry points. While there are currently no identified vulnerabilities in the plugin's history or specific critical/high-severity taint flows, this lack of authentication and authorization mechanisms represents a potential weakness. If any new vulnerabilities are introduced in future versions or if an unexpected entry point is discovered, these checks would be crucial for preventing unauthorized actions or data breaches. The plugin's history of zero known CVEs is a positive indicator of its past security, but it does not guarantee future immunity, especially without robust authorization checks.

In conclusion, 'acf-date-time-picker' v1.1.4 has strengths in its limited attack surface and secure data handling (SQL prepared statements, output escaping). However, the lack of nonce and capability checks is a significant gap that could be exploited. This makes the plugin's security reliant on the absence of exploitable flaws rather than active defense against unauthorized access.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Date & Time Picker for Advanced Custom Fields Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Date & Time Picker for Advanced Custom Fields Release Timeline

v1.1.4Current
v1.1.3
v1.1.2
v1.1.1
v1.1.0
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Date & Time Picker for Advanced Custom Fields Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
32 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

84% escaped38 total outputs
Attack Surface

Date & Time Picker for Advanced Custom Fields Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionacf/include_field_typesacf-date_time_picker.php:37
actionacf/register_fieldsacf-date_time_picker.php:38
actioninitfields\acf-date_time_picker-v4.php:48
actioninitfields\acf-date_time_picker-v5.php:30
Maintenance & Trust

Date & Time Picker for Advanced Custom Fields Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedMay 3, 2016
PHP min version
Downloads8K

Community Trust

Rating20/100
Number of ratings1
Active installs300
Developer Profile

Date & Time Picker for Advanced Custom Fields Developer Profile

Bartosz Romanowski

2 plugins · 310 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Date & Time Picker for Advanced Custom Fields

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/acf-date-time-picker/assets/css/jquery-ui-timepicker-addon.min.css/wp-content/plugins/acf-date-time-picker/assets/js/jquery-ui-timepicker/jquery-ui-timepicker-addon.min.js/wp-content/plugins/acf-date-time-picker/assets/js/jquery-ui-timepicker/jquery-ui-sliderAccess.js/wp-content/plugins/acf-date-time-picker/assets/js/input.js
Script Paths
jquery-ui-timepickeracf-jquery-ui-timepickeracf-jquery-ui-slideraccessacf-input-date_time_picker
Version Parameters
acf-jquery-ui-timepicker-addon.min.css?ver=1.1.4jquery-ui-timepicker-addon.min.js?ver=1.1.4jquery-ui-sliderAccess.js?ver=1.1.4input.js?ver=1.1.4

HTML / DOM Fingerprints

CSS Classes
acf-date_time_picker
Data Attributes
data-field-typedata-date-formatdata-time-formatdata-first-daydata-time-selectordata-past-dates
FAQ

Frequently Asked Questions about Date & Time Picker for Advanced Custom Fields