ACF Fold Flexible Content Security & Risk Analysis

wordpress.org/plugins/acf-fold-flexible-content

A simple plugin for enhancing the ACF Flexible Content Field. Collapsed flexible content panels with helping icons.

400 active installs v1.4.1 PHP + WP 3.0+ Updated Oct 3, 2016
acfadvanced-custom-fieldscollapsecustom-fieldsfields
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ACF Fold Flexible Content Safe to Use in 2026?

Generally Safe

Score 85/100

ACF Fold Flexible Content has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "acf-fold-flexible-content" v1.4.1 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any identified dangerous functions, external HTTP requests, file operations, and the use of prepared statements for all SQL queries demonstrate good development practices. Furthermore, the lack of reported vulnerabilities, including critical or high severity issues, and the absence of any recorded historical exploits indicate a well-maintained and secure plugin. The code analysis also shows no evidence of taint flows or unsanitized paths, reinforcing its robustness against common injection attacks.

While the plugin's current state appears highly secure, it's important to note the absence of some security mechanisms like nonce checks and capability checks. Although the static analysis shows zero unprotected entry points, the lack of these checks could potentially become a concern if new entry points or vulnerabilities are introduced in future versions or if the plugin interacts with other components that might expose these weaknesses. However, based solely on the current data, the plugin presents a minimal security risk to WordPress installations. Its clean vulnerability history and secure coding practices are significant strengths.

Vulnerabilities
None known

ACF Fold Flexible Content Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ACF Fold Flexible Content Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

ACF Fold Flexible Content Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_print_stylesacf-fold-flexible.php:42
actionadmin_enqueue_scriptsacf-fold-flexible.php:43
Maintenance & Trust

ACF Fold Flexible Content Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedOct 3, 2016
PHP min version
Downloads18K

Community Trust

Rating96/100
Number of ratings4
Active installs400
Developer Profile

ACF Fold Flexible Content Developer Profile

currencywiki

17 plugins · 4K total installs

80
trust score
Avg Security Score
89/100
Avg Patch Time
35 days
View full developer profile
Detection Fingerprints

How We Detect ACF Fold Flexible Content

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/acf-fold-flexible-content/css/acf-fold-flexible.admin.css/wp-content/plugins/acf-fold-flexible-content/js/acf-fold-flexible.admin.pro.js/wp-content/plugins/acf-fold-flexible-content/js/acf-fold-flexible.admin.js/wp-content/plugins/acf-fold-flexible-content/js/acf-fold-flexible.tooltip.js
Script Paths
acf-fold-flexible-content/js/acf-fold-flexible.admin.pro.jsacf-fold-flexible-content/js/acf-fold-flexible.admin.jsacf-fold-flexible-content/js/acf-fold-flexible.tooltip.js

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about ACF Fold Flexible Content