
ACF Post Object Elementor List Widget Security & Risk Analysis
wordpress.org/plugins/acf-post-object-elementor-list-widgetA WordPress Plugin that adds the ability to display the contents of an ACF Post Object field as a list of post links.
Is ACF Post Object Elementor List Widget Safe to Use in 2026?
Generally Safe
Score 85/100ACF Post Object Elementor List Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of 'acf-post-object-elementor-list-widget' v0.5.0 reveals an excellent security posture in several key areas. The plugin has no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero attack surface. Furthermore, there are no dangerous functions, file operations, external HTTP requests, or bundled libraries to scrutinize. The complete absence of known vulnerabilities in its history is also a significant positive indicator.
However, a critical concern arises from the output escaping. With one total output identified and 0% properly escaped, this presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed to users that originates from user input or external sources is potentially vulnerable if not correctly sanitized. The lack of nonce checks and capability checks, while not explicitly flagged as risky in this version due to the absence of certain entry points, could become a vulnerability if new entry points are introduced in future updates.
In conclusion, while the plugin demonstrates strong foundational security practices by minimizing its attack surface and avoiding common pitfalls like raw SQL queries, the unescaped output is a glaring weakness. This single vulnerability, if exploited, could have serious consequences. The absence of a vulnerability history is positive but should not lead to complacency, especially given the noted output escaping issue.
Key Concerns
- Unescaped output detected
ACF Post Object Elementor List Widget Security Vulnerabilities
ACF Post Object Elementor List Widget Code Analysis
Output Escaping
ACF Post Object Elementor List Widget Attack Surface
WordPress Hooks 7
Maintenance & Trust
ACF Post Object Elementor List Widget Maintenance & Trust
Maintenance Signals
Community Trust
ACF Post Object Elementor List Widget Alternatives
Qi Addons For Elementor
qi-addons-for-elementor
Qi Addons for Elementor is a comprehensive library of 60+ custom, flexible & easily styled Elementor widgets developed by Qode Interactive.
MT Addons for Elementor
mt-addons-for-elementor
MT Addons for Elementor with 50+ widgets, crafted by ModelTheme for dynamic, stylish website creation.
Wadi Addons for Elementor
wadi-addons-for-elementor
Wadi Addons for Elementor Page Builder provides a collection of quality Elementor Widgets which powers your Elementor Page Builder and takes your page …
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
ACF Post Object Elementor List Widget Developer Profile
1 plugin · 20 total installs
How We Detect ACF Post Object Elementor List Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/acf-post-object-elementor-list-widget/widget.phpacf-post-object-elementor-list-widget/widget.php?ver=