
ACF Pro show fields shortcode Security & Risk Analysis
wordpress.org/plugins/acf-pro-show-fields-shortcodeIf you use ACF Pro, you can display some fields on your pages with shortcode. e.g. [mxasts_acfp_show_field debug="true" get_field="card …
Is ACF Pro show fields shortcode Safe to Use in 2026?
Generally Safe
Score 100/100ACF Pro show fields shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "acf-pro-show-fields-shortcode" v1.1 presents a mixed security posture. On the positive side, it has a very small attack surface with only one entry point, a shortcode, and no identified AJAX handlers, REST API routes, or cron events that are exposed without authentication. Furthermore, there are no known CVEs associated with this plugin, and the static analysis did not reveal any critical or high severity taint flows. This suggests a generally well-contained and unexploited plugin.
However, significant concerns arise from the static code analysis. The plugin exhibits a complete lack of output escaping, meaning any data displayed through the shortcode could be vulnerable to cross-site scripting (XSS) attacks if the data originates from an untrusted source. Additionally, all three SQL queries are executed without prepared statements, introducing a risk of SQL injection vulnerabilities. The absence of nonce checks and capability checks further weakens its security, as there are no built-in protections against unauthorized actions or privilege escalation through its functionalities. The vulnerability history being clean is positive, but it doesn't mitigate the immediate risks identified in the code.
In conclusion, while the plugin has a limited attack surface and no known historical vulnerabilities, the findings of unescaped output and raw SQL queries present tangible security risks that require immediate attention. The absence of any authorization checks on its single entry point amplifies these concerns. Addressing these specific code-level vulnerabilities is crucial to improving the plugin's overall security.
Key Concerns
- All SQL queries use raw execution
- No output escaping found
- No nonce checks found
- No capability checks found
ACF Pro show fields shortcode Security Vulnerabilities
ACF Pro show fields shortcode Code Analysis
SQL Query Safety
Output Escaping
ACF Pro show fields shortcode Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
ACF Pro show fields shortcode Maintenance & Trust
Maintenance Signals
Community Trust
ACF Pro show fields shortcode Alternatives
ACF Clone Repeater
acf-clone-repeater
ACF Pro 5.9 comes with a duplicate row feature on its own.
Advanced Custom Fields YITH WooCommerce Compare support
acf-yith-woocommerce-compare-support
Advanced Custom Fields YITH WooCommerce Compare support
wp-Typography Disable ACF Integration
wp-typography-disable-acf-integration
Disables wp-Typography ACF Integration.
ACF Pro show fields shortcode Developer Profile
11 plugins · 1K total installs
How We Detect ACF Pro show fields shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/acf-pro-show-fields-shortcode/assets/font-awesome-4.6.3/css/font-awesome.min.css/wp-content/plugins/acf-pro-show-fields-shortcode/includes/frontend/assets/css/style.css/wp-content/plugins/acf-pro-show-fields-shortcode/includes/frontend/assets/js/script.js/wp-content/plugins/acf-pro-show-fields-shortcode/includes/frontend/assets/js/script.jsacf-pro-show-fields-shortcode/includes/frontend/assets/css/style.css?ver=acf-pro-show-fields-shortcode/includes/frontend/assets/js/script.js?ver=HTML / DOM Fingerprints
<pre>Debugging mode<br>var_dump('debug = 'var_dump('get_field = 'get_field value = get_fields =