
ACF My Media Cluster Security & Risk Analysis
wordpress.org/plugins/acf-my-media-clusterACF My Media Cluster is an extension for the Advance Custom Fields plugin, which adds the ability to create groups of media files for download on a pa …
Is ACF My Media Cluster Safe to Use in 2026?
Generally Safe
Score 100/100ACF My Media Cluster has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "acf-my-media-cluster" v1.2.12 plugin exhibits a concerning security posture, primarily due to a significant number of unprotected entry points. Three out of the four identified entry points, specifically AJAX handlers, lack authentication checks. This means that any unauthenticated user could potentially interact with these endpoints, leading to unauthorized actions. The presence of the `unserialize` function is a critical red flag, as it can be exploited if fed with malicious serialized data, potentially leading to remote code execution. While no critical or high-severity taint flows were identified, the two flows with unsanitized paths are still a concern, indicating potential vulnerabilities if exploited. The plugin's history of zero known CVEs is a positive indicator, suggesting a relatively stable codebase or perhaps a lack of historical scrutiny. However, this positive history is overshadowed by the immediate risks presented by the unprotected AJAX handlers and the dangerous `unserialize` function. In conclusion, while the plugin benefits from a clean vulnerability history and proper output escaping, the identified unprotected entry points and the use of a dangerous function significantly elevate its risk profile.
Key Concerns
- Unprotected AJAX handlers
- Use of unserialize function
- SQL queries without prepared statements
- Taint flows with unsanitized paths
ACF My Media Cluster Security Vulnerabilities
ACF My Media Cluster Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
ACF My Media Cluster Attack Surface
AJAX Handlers 3
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
ACF My Media Cluster Maintenance & Trust
Maintenance Signals
Community Trust
ACF My Media Cluster Alternatives
Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files
embed-any-document
Embed PDF, DOC, PPT and XLS documents easily on your WordPress website with the help of Google Docs Viewer or Microsoft Office Online.
Document Gallery
document-gallery
This plugin generates thumbnails for documents and displays them in a gallery-like format for easy sharing.
FileBird Document Library
filebird-document-library
Create WordPress document library using FileBird and Gutenberg or any WordPress page builder.
Document Gallery – Display PDF Gallery from Many Folders
catfolders-document-gallery
Display WordPress PDF gallery and file gallery from folder. Comes with a clean, searchable & sortable list/grid layout.
HM Books Gallery – Build a Book Showcase, Store or a Library in minutes
wp-books-gallery
Book Gallery will build a mobile-friendly Book Store, Showcase or Library in a few minutes. You can also display pdfs, documents in a grid/list view.
ACF My Media Cluster Developer Profile
3 plugins · 4K total installs
How We Detect ACF My Media Cluster
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/acf-my-media-cluster/assets/css/acf-media-cluster.css/wp-content/plugins/acf-my-media-cluster/assets/js/acf-media-cluster.js/wp-content/plugins/acf-my-media-cluster/assets/js/acf-media-cluster.js?ver=1.2.12HTML / DOM Fingerprints
acf-media-cluster-wrapper<!-- Include the code for the media cluster field group --><!-- Include code for the model edit window for individual files attached to the media cluster field --><!-- Save edits made in the modal edit window for individual files -->data-acf_media_cluster_field_keydata-acf_media_cluster_post_iddata-acf_media_cluster_field_nameacf_media_cluster_params/wp-json/acf/v1/media-cluster-edit-fields/wp-json/acf/v1/media-cluster-edit-save-field