
ACF: User Role Selector Security & Risk Analysis
wordpress.org/plugins/acf-role-selector-fieldA field for Advanced Custom Fields which allows you to select one or more user roles
Is ACF: User Role Selector Safe to Use in 2026?
Generally Safe
Score 85/100ACF: User Role Selector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of acf-role-selector-field v3.0.2 reveals a generally strong security posture. The plugin reports zero AJAX handlers, REST API routes, shortcodes, or cron events, resulting in no discernible attack surface and no unprotected entry points. Furthermore, the absence of dangerous functions, external HTTP requests, and file operations is commendable. All detected SQL queries are correctly implemented using prepared statements. However, a significant concern arises from the complete lack of output escaping, with 0% of 27 total outputs being properly escaped. This indicates a high probability of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data is likely being rendered directly into the HTML without sanitization.
The vulnerability history is clean, with no recorded CVEs, suggesting a good track record. The taint analysis also reports zero flows, which is positive. Despite the clean vulnerability history and robust handling of SQL and entry points, the pervasive lack of output escaping is a critical weakness that needs immediate attention. This single issue significantly elevates the risk profile of the plugin, potentially exposing users to XSS attacks that could lead to session hijacking, defacement, or further malicious actions. While other areas show good security practices, the unescaped output is a glaring omission that overshadows these strengths.
Key Concerns
- 0% output escaping
ACF: User Role Selector Security Vulnerabilities
ACF: User Role Selector Code Analysis
Output Escaping
ACF: User Role Selector Attack Surface
WordPress Hooks 3
Maintenance & Trust
ACF: User Role Selector Maintenance & Trust
Maintenance Signals
Community Trust
ACF: User Role Selector Alternatives
Advanced Custom Fields (ACF®)
advanced-custom-fields
ACF helps customize WordPress with powerful, professional and intuitive fields. Proudly powering over 2 million sites, WordPress developers love ACF.
ACF Content Analysis for Yoast SEO
acf-content-analysis-for-yoast-seo
WordPress plugin that adds the content of all ACF fields to the Yoast SEO score analysis.
Advanced Custom Fields: Extended
acf-extended
All-in-one enhancement suite that improves WordPress & Advanced Custom Fields.
Advanced Custom Fields: Font Awesome Field
advanced-custom-fields-font-awesome
Adds a new 'Font Awesome Icon' field to the popular Advanced Custom Fields plugin.
Table Field Add-on for ACF and SCF
advanced-custom-fields-table-field
A Table Field Add-on for the Advanced Custom Fields and Secure Custom Fields Plugin.
ACF: User Role Selector Developer Profile
12 plugins · 7K total installs
How We Detect ACF: User Role Selector
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/acf-role-selector-field/css/acf-role-selector-field.css/wp-content/plugins/acf-role-selector-field/js/acf-role-selector-field.js/wp-content/plugins/acf-role-selector-field/js/acf-role-selector-field.jsacf-role-selector-field/css/acf-role-selector-field.css?ver=acf-role-selector-field/js/acf-role-selector-field.js?ver=HTML / DOM Fingerprints
acf-role-selector-field