Blocks for ACF Fields — Display Custom Fields in the Block Editor Security & Risk Analysis

wordpress.org/plugins/acf-field-blocks

The easiest way to load ACF & SCF fields in WordPress blocks. Add your custom fields to the block editor instantly — no coding required!

1K active installs v1.4.3 PHP 7.4+ WP 6.5+ Updated Mar 9, 2026
acfacf-blockblockmeta-fieldmeta-field-block
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Blocks for ACF Fields — Display Custom Fields in the Block Editor Safe to Use in 2026?

Generally Safe

Score 100/100

Blocks for ACF Fields — Display Custom Fields in the Block Editor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 25d ago
Risk Assessment

The plugin "acf-field-blocks" v1.4.3 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. The code analysis reveals excellent adherence to secure coding practices, with all SQL queries using prepared statements, a very high percentage of outputs properly escaped, and the presence of nonce and capability checks. The lack of any identified dangerous functions, file operations, or external HTTP requests further bolsters its security. The complete absence of known CVEs and a clean vulnerability history suggest a well-maintained and secure plugin. The taint analysis showing no unsanitized paths or critical/high severity flows reinforces this positive assessment. This plugin appears to be developed with security as a high priority.

Vulnerabilities
None known

Blocks for ACF Fields — Display Custom Fields in the Block Editor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Blocks for ACF Fields — Display Custom Fields in the Block Editor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
56 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

97% escaped58 total outputs
Attack Surface

Blocks for ACF Fields — Display Custom Fields in the Block Editor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 18
actionadmin_noticesacf-field-blocks.php:54
actionafter_setup_themeacf-field-blocks.php:58
actionadmin_noticesacf-field-blocks.php:60
filternetwork_admin_plugin_action_links_acf-field-blocks/acf-field-blocks.phpacf-field-blocks.php:64
filterplugin_action_links_acf-field-blocks/acf-field-blocks.phpacf-field-blocks.php:65
actionactivated_pluginacf-field-blocks.php:66
actionpre_current_active_pluginsacf-field-blocks.php:67
actionadmin_initacf-field-blocks.php:68
actionadmin_noticesacf-field-blocks.php:100
actionplugins_loadedacf-field-blocks.php:228
filterblock_categories_allinc\class-blocks.php:85
actioninitinc\class-blocks.php:86
actionenqueue_block_assetsinc\class-blocks.php:87
actionenqueue_block_editor_assetsinc\class-blocks.php:88
actionenqueue_block_assetsinc\class-blocks.php:89
filterthe_contentinc\class-blocks.php:200
filterwp_footerinc\class-blocks.php:220
actionrest_api_initinc\class-rest.php:58
Maintenance & Trust

Blocks for ACF Fields — Display Custom Fields in the Block Editor Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 9, 2026
PHP min version7.4
Downloads12K

Community Trust

Rating98/100
Number of ratings8
Active installs1K
Developer Profile

Blocks for ACF Fields — Display Custom Fields in the Block Editor Developer Profile

gamaup

1 plugin · 1K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Blocks for ACF Fields — Display Custom Fields in the Block Editor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/acf-field-blocks/build/index.js/wp-content/plugins/acf-field-blocks/build/style.css
Script Paths
/wp-content/plugins/acf-field-blocks/build/index.js
Version Parameters
acf-field-blocks/build/index.js?ver=acf-field-blocks/build/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
acf-field-blocks-acf-blocks-wrapper
HTML Comments
acf-field-blocks.php
Data Attributes
data-acf-field-blocks-id
JS Globals
acfFieldBlocksSettings
REST Endpoints
/wp-json/acf-field-blocks/v1/blocks
FAQ

Frequently Asked Questions about Blocks for ACF Fields — Display Custom Fields in the Block Editor