ACF Flexible Content Layout Thumbnail Security & Risk Analysis

wordpress.org/plugins/acf-flexible-content-layout-thumbnail

Extend Advanced Custom Fields PRO - add thumbnail layout to flexible content

10 active installs v1.0.0 PHP + WP 4.8+ Updated Jul 11, 2018
acfadvanced-custom-fieldsfieldfieldsflexible
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ACF Flexible Content Layout Thumbnail Safe to Use in 2026?

Generally Safe

Score 85/100

ACF Flexible Content Layout Thumbnail has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "acf-flexible-content-layout-thumbnail" plugin, version 1.0.0, exhibits a mixed security posture. On the positive side, it demonstrates good practices by having no known CVEs, no external HTTP requests, no file operations, and no SQL queries that don't use prepared statements. The attack surface is also minimal, with zero identified entry points like AJAX handlers, REST API routes, or shortcodes, and no cron events. This suggests a generally well-contained plugin.

However, there are significant concerns stemming from the code analysis. A notable weakness is the 60% of output that is not properly escaped, presenting a clear risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is displayed without adequate sanitization. Furthermore, the taint analysis reveals two flows with unsanitized paths, indicating potential vulnerabilities where data could be manipulated in unexpected ways, although no critical or high severity issues were flagged here. The absence of nonce checks and capability checks on any potential, albeit undocumented, entry points is also a significant concern, leaving the plugin vulnerable to CSRF and unauthorized access if any internal functionality were to be exposed.

Considering the lack of historical vulnerabilities, it's difficult to infer long-term patterns. This could mean the plugin is new, has been maintained diligently, or simply hasn't been targeted or thoroughly audited. The current analysis highlights the immediate risks associated with unescaped output and unsanitized paths. While the lack of an attack surface is a strength, the unaddressed output escaping and unsanitized paths are critical weaknesses that require attention to improve the plugin's overall security.

Key Concerns

  • Unescaped output detected (40% escaped)
  • Taint analysis shows unsanitized paths
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

ACF Flexible Content Layout Thumbnail Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ACF Flexible Content Layout Thumbnail Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

40% escaped15 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
submit_data (includes\class-meta-boxes.php:96)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ACF Flexible Content Layout Thumbnail Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_noticesacf-fcl.php:107
filteracf/fields/flexible_content/layout_titleacf-fcl.php:108
actionadmin_noticesacf-fcl.php:166
actionadmin_menuincludes\class-menus.php:24
actionadd_meta_boxesincludes\class-meta-boxes.php:23
actionadmin_enqueue_scriptsincludes\class-meta-boxes.php:26
actioninitincludes\class-meta-boxes.php:27
filterscreen_layout_columnsincludes\class-meta-boxes.php:28
Maintenance & Trust

ACF Flexible Content Layout Thumbnail Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJul 11, 2018
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

ACF Flexible Content Layout Thumbnail Developer Profile

webcentar

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ACF Flexible Content Layout Thumbnail

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/acf-flexible-content-layout-thumbnail/assets/images/noImage.png

HTML / DOM Fingerprints

JS Globals
acf_fcl
FAQ

Frequently Asked Questions about ACF Flexible Content Layout Thumbnail