ACF OpenStreetMap Field Security & Risk Analysis

wordpress.org/plugins/acf-openstreetmap-field

A configurable OpenStreetMap Field for ACF.

9K active installs v1.6.1 PHP 5.6+ WP 4.8+ Updated Dec 22, 2024
map-acf-openstreetmap-leaflet
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ACF OpenStreetMap Field Safe to Use in 2026?

Generally Safe

Score 92/100

ACF OpenStreetMap Field has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The acf-openstreetmap-field plugin v1.6.1 exhibits a strong security posture based on the provided static analysis. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events with potential attack surfaces, coupled with no identified dangerous functions, raw SQL queries, or critical taint flows, indicates robust security development practices. The high percentage of properly escaped output and the use of prepared statements for SQL queries further reinforce this positive assessment. The plugin's vulnerability history is also clear, with no known CVEs, suggesting a lack of past exploitable issues. However, the presence of file operations, while not inherently problematic, warrants attention to ensure they are implemented securely. The lack of explicit nonce and capability checks on any identified entry points (though none were found) is a point of note, as it could become a concern if new entry points are introduced in future versions. Overall, this plugin appears to be secure in its current state, with a low risk profile due to its minimal attack surface and well-implemented code signals. The primary areas for continued vigilance would be in how any file operations are handled and the continued absence of exploitable vulnerabilities.

Key Concerns

  • No nonce checks on potential entry points
  • No capability checks on potential entry points
  • Presence of file operations
Vulnerabilities
None known

ACF OpenStreetMap Field Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ACF OpenStreetMap Field Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
38 escaped
Nonce Checks
0
Capability Checks
2
File Operations
4
External Requests
0
Bundled Libraries
0

Output Escaping

86% escaped44 total outputs
Attack Surface

ACF OpenStreetMap Field Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 21
actionacf/include_field_typesinclude\ACFFieldOpenstreetmap\Compat\ACF.php:15
filterpolylang_acf_sync_supported_fieldsinclude\ACFFieldOpenstreetmap\Compat\ACF.php:18
actionacf/input/admin_enqueue_scriptsinclude\ACFFieldOpenstreetmap\Compat\ACF.php:20
actionacf/include_field_typesinclude\ACFFieldOpenstreetmap\Core\Core.php:19
actioninitinclude\ACFFieldOpenstreetmap\Core\Core.php:21
actionwp_enqueue_scriptsinclude\ACFFieldOpenstreetmap\Core\Core.php:23
actionlogin_enqueue_scriptsinclude\ACFFieldOpenstreetmap\Core\Core.php:25
actionadmin_enqueue_scriptsinclude\ACFFieldOpenstreetmap\Core\Core.php:28
filteracf_osm_leaflet_providersinclude\ACFFieldOpenstreetmap\Core\MapProxy.php:20
actionupdate_option_acf_osm_provider_tokensinclude\ACFFieldOpenstreetmap\Core\MapProxy.php:23
actionupdate_option_acf_osm_providersinclude\ACFFieldOpenstreetmap\Core\MapProxy.php:24
actionupdate_option_acf_osm_proxyinclude\ACFFieldOpenstreetmap\Core\MapProxy.php:25
actionadmin_initinclude\ACFFieldOpenstreetmap\Core\Plugin.php:31
filterextra_plugin_headersinclude\ACFFieldOpenstreetmap\Core\Plugin.php:32
actionplugins_loadedinclude\ACFFieldOpenstreetmap\Core\Plugin.php:34
actionget_template_partinclude\ACFFieldOpenstreetmap\Core\Templates.php:27
actionprint_media_templatesinclude\ACFFieldOpenstreetmap\Field\OpenStreetMap.php:72
actionwp_footerinclude\ACFFieldOpenstreetmap\Field\OpenStreetMap.php:391
actionadmin_initinclude\ACFFieldOpenstreetmap\Settings\Settings.php:18
actionadmin_menuinclude\ACFFieldOpenstreetmap\Settings\SettingsOpenStreetMap.php:27
actionload-settings_page_acf_osminclude\ACFFieldOpenstreetmap\Settings\SettingsOpenStreetMap.php:28
Maintenance & Trust

ACF OpenStreetMap Field Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 22, 2024
PHP min version5.6
Downloads134K

Community Trust

Rating92/100
Number of ratings24
Active installs9K
Alternatives

ACF OpenStreetMap Field Alternatives

No alternatives data available yet.

Developer Profile

ACF OpenStreetMap Field Developer Profile

podpirate

6 plugins · 51K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
345 days
View full developer profile
Detection Fingerprints

How We Detect ACF OpenStreetMap Field

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/acf-openstreetmap-field/assets/css/acf-osm-leaflet.css/wp-content/plugins/acf-openstreetmap-field/assets/js/acf-osm-frontend.js/wp-content/plugins/acf-openstreetmap-field/assets/js/acf-input-osm.js/wp-content/plugins/acf-openstreetmap-field/assets/css/acf-input-osm.css
Script Paths
/wp-content/plugins/acf-openstreetmap-field/assets/js/acf-osm-frontend.js/wp-content/plugins/acf-openstreetmap-field/assets/js/acf-input-osm.js
Version Parameters
acf-openstreetmap-field/assets/css/acf-osm-leaflet.css?ver=acf-openstreetmap-field/assets/js/acf-osm-frontend.js?ver=acf-openstreetmap-field/assets/js/acf-input-osm.js?ver=acf-openstreetmap-field/assets/css/acf-input-osm.css?ver=

HTML / DOM Fingerprints

CSS Classes
acf-osm-marker-icon
JS Globals
acf_osmacf_osm_admin
FAQ

Frequently Asked Questions about ACF OpenStreetMap Field