Add Ionicon Field for ACF Security & Risk Analysis
wordpress.org/plugins/acf-ionicon-fieldAdds a new 'Ionicon' field to Advanced Custom Fields plugin.
Is Add Ionicon Field for ACF Safe to Use in 2026?
Generally Safe
Score 85/100Add Ionicon Field for ACF has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The acf-ionicon-field plugin v1.0.0 exhibits a mixed security posture. On the positive side, its static analysis reveals good practices in areas such as SQL query preparation and output escaping, with 100% of observed instances being secure. The absence of known vulnerabilities (CVEs) in its history is also a strong indicator of a well-maintained and secure codebase to date. Furthermore, no critical or high-severity taint flows were identified, suggesting that the handling of potentially malicious data is generally robust.
However, a significant concern arises from the plugin's attack surface. It exposes one AJAX handler that lacks any authentication checks. This unprotected entry point could potentially be exploited by unauthenticated users to trigger unintended actions or gain information, depending on the functionality of that AJAX handler. The lack of capability checks further exacerbates this risk, as it bypasses WordPress's user role and permission system. While there are no currently documented vulnerabilities, the presence of an unprotected AJAX endpoint represents a tangible security weakness that could be targeted.
In conclusion, while the plugin demonstrates strengths in data handling and has a clean vulnerability history, the unprotected AJAX endpoint is a critical flaw that needs immediate attention. The absence of nonce and capability checks on this entry point significantly increases its exploitability. Addressing this specific weakness should be the priority for improving the plugin's overall security.
Key Concerns
- AJAX handler without authentication check
- AJAX handler without capability checks
- Lack of nonce checks on entry points
Add Ionicon Field for ACF Security Vulnerabilities
Add Ionicon Field for ACF Code Analysis
Output Escaping
Add Ionicon Field for ACF Attack Surface
AJAX Handlers 1
WordPress Hooks 5
Maintenance & Trust
Add Ionicon Field for ACF Maintenance & Trust
Maintenance Signals
Community Trust
Add Ionicon Field for ACF Alternatives
ACF Content Analysis for Yoast SEO
acf-content-analysis-for-yoast-seo
WordPress plugin that adds the content of all ACF fields to the Yoast SEO score analysis.
Advanced Custom Fields: Font Awesome Field
advanced-custom-fields-font-awesome
Adds a new 'Font Awesome Icon' field to the popular Advanced Custom Fields plugin.
Table Field Add-on for ACF and SCF
advanced-custom-fields-table-field
A Table Field Add-on for the Advanced Custom Fields and Secure Custom Fields Plugin.
ACF: Better Search
acf-better-search
This plugin adds to default WordPress search engine the ability to search by content from selected fields of Advanced Custom Fields plugin.
WP All Import – Import Add-On for ACF
csv-xml-import-for-acf
Drag & drop to import any CSV, Excel, XML, or Google Sheets file into Advanced Custom Fields. Supports repeaters, flexible content, galleries, and …
Add Ionicon Field for ACF Developer Profile
1 plugin · 10 total installs
How We Detect Add Ionicon Field for ACF
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/acf-ionicon-field/assets/css/acf-ionicon-field.css/wp-content/plugins/acf-ionicon-field/assets/js/acf-ionicon-field.js/wp-content/plugins/acf-ionicon-field/assets/js/acf-ionicon-field.jsacf-ionicon-field/assets/css/acf-ionicon-field.css?ver=acf-ionicon-field/assets/js/acf-ionicon-field.js?ver=HTML / DOM Fingerprints
acf-ionicon-fieldionicon-createdata-field_type="ionicon"acf.fields.ionicon/wp-json/acf/fields/ionicon/query