
ACF Media Cluster Security & Risk Analysis
wordpress.org/plugins/acf-media-clusterACF Media Cluster is an extension for Advance Custom Fields which adds the feature to add multiple media to post/pages.
Is ACF Media Cluster Safe to Use in 2026?
Generally Safe
Score 85/100ACF Media Cluster has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The acf-media-cluster v1.0.0 plugin exhibits a concerning security posture due to a significant number of unprotected entry points. While the plugin demonstrates good practices by avoiding dangerous functions, performing only prepared SQL queries, and not making external HTTP requests, the lack of authentication checks on three out of four total entry points is a major weakness. This exposes the plugin to potential unauthorized access and manipulation. The taint analysis shows four flows with unsanitized paths, which, while not classified as critical or high severity in this analysis, warrant further investigation as they represent potential avenues for data manipulation if not handled correctly by the application layer. The plugin's vulnerability history is clean, indicating no previously discovered CVEs. This is a positive sign, but it does not negate the risks presented by the current code analysis.
Key Concerns
- AJAX handlers without auth checks
- Flows with unsanitized paths
- Output escaping is below 70%
- Missing nonce checks on AJAX
- Missing capability checks on AJAX
ACF Media Cluster Security Vulnerabilities
ACF Media Cluster Release Timeline
ACF Media Cluster Code Analysis
Output Escaping
Data Flow Analysis
ACF Media Cluster Attack Surface
AJAX Handlers 3
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
ACF Media Cluster Maintenance & Trust
Maintenance Signals
Community Trust
ACF Media Cluster Alternatives
Media Carousel ACF Field
media-carousel-acf-field
Displays images and videos in a carousel fetched from Advanced Custom Fields (ACF).
ACF Galerie 4
acf-galerie-4
Enhance your WordPress website with ACF Galerie 4, a powerful and customizable gallery plugin.
WP Image Importer
wp-image-importer
WP Image Importer plugin allows you to easily insert image into your wordpress post from facebook, flickr and pixabay
ACF My Media Cluster
acf-my-media-cluster
ACF My Media Cluster is an extension for the Advance Custom Fields plugin, which adds the ability to create groups of media files for download on a pa …
FileBird – WordPress Media Library Folders & File Manager
filebird
Organize thousands of WordPress media files in folders / categories with ease.
ACF Media Cluster Developer Profile
5 plugins · 61K total installs
How We Detect ACF Media Cluster
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/acf-media-cluster/assets/css/acf-media-cluster.css/wp-content/plugins/acf-media-cluster/assets/js/acf-media-cluster.js/wp-content/plugins/acf-media-cluster/assets/js/acf-media-cluster.jsacf-media-cluster.css?ver=acf-media-cluster.js?ver=HTML / DOM Fingerprints
acf-mc-sc-outputacf-mc-sc-output-rowacf-mc-sc-output-titleacf-mc-sc-output-captionacf-mc-sc-output-downloaddata-acf-mc-field-keyacf_media_cluster_optsacf_mc_cluster_edit_save_field_ajax/wp-json/acf/v1/media-cluster-edit-fields/wp-json/acf/v1/acf_mc_cluster_field_group/wp-json/acf/v1/acf_mc_cluster_edit_fields/wp-json/acf/v1/acf_mc_cluster_edit_save_field<div class="acf-mc-sc-output<thead class="acf-mc-sc-output-row"><th class="acf-mc-sc-output-title">Title</th><th class="acf-mc-sc-output-caption">Caption</th>