
ACF: Star Rating Field Security & Risk Analysis
wordpress.org/plugins/acf-starrating"Star rating" field. Add-on to Advanced Custom Fields plugin.
Is ACF: Star Rating Field Safe to Use in 2026?
Generally Safe
Score 85/100ACF: Star Rating Field has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The acf-starrating plugin version 1.0.2 presents a mixed security posture. On the positive side, it boasts a small attack surface with only two AJAX handlers, and crucially, none of these entry points are unprotected by authentication checks. Furthermore, the plugin demonstrates a strong commitment to data integrity by utilizing prepared statements for 92% of its SQL queries, and there's a single nonce check present, indicating some awareness of cross-site request forgery prevention. The complete absence of known CVEs and a clean vulnerability history are also significant strengths.
However, there are notable areas of concern. The taint analysis reveals three flows with unsanitized paths, all flagged as high severity. This suggests that user-supplied data might be making its way into sensitive operations without adequate sanitization, posing a potential risk. Compounding this, the plugin exhibits very poor output escaping practices, with only 11% of outputs being properly escaped. This significantly increases the likelihood of cross-site scripting (XSS) vulnerabilities, especially when combined with the unsanitized data flows.
In conclusion, while the plugin has strengths in its limited attack surface, lack of critical CVEs, and use of prepared statements, the high-severity unsanitized taint flows and extremely low rate of output escaping represent significant security weaknesses. These issues could be exploited to achieve arbitrary code execution or inject malicious scripts, despite the existing authentication and nonce checks. Mitigation of these output escaping and data sanitization issues should be a priority.
Key Concerns
- High severity unsanitized taint flows
- Low output escaping rate
- No capability checks on entry points
ACF: Star Rating Field Security Vulnerabilities
ACF: Star Rating Field Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ACF: Star Rating Field Attack Surface
AJAX Handlers 2
WordPress Hooks 8
Maintenance & Trust
ACF: Star Rating Field Maintenance & Trust
Maintenance Signals
Community Trust
ACF: Star Rating Field Alternatives
Advanced Custom Fields: Nav Menu Field
advanced-custom-fields-nav-menu-field
Add-On plugin for Advanced Custom Fields (ACF) that adds a 'Nav Menu' Field type.
Advanced Custom Fields: Limiter Field
advanced-custom-fields-limiter-field
This plugin provides a textarea that limits the number of characters a user can add. The limit is cleanly represented by a jQuery UI progress bar.
Advanced Custom Fields: Markdown Field
advanced-custom-fields-markdown
Adds a markdown-field.
Advanced Custom Fields: Leaflet Field
advanced-custom-fields-leaflet-field
Addon for Advanced Custom Fields that adds a Leaflet field to the available field types.
ACF Content Analysis for Yoast SEO
acf-content-analysis-for-yoast-seo
WordPress plugin that adds the content of all ACF fields to the Yoast SEO score analysis.
ACF: Star Rating Field Developer Profile
1 plugin · 300 total installs
How We Detect ACF: Star Rating Field
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/acf-starrating/css/jquery.rating.css/wp-content/plugins/acf-starrating/js/jquery.rating.js/wp-content/plugins/acf-starrating/js/jquery.rating.jsacf-starrating/css/jquery.rating.css?ver=acf-starrating/js/jquery.rating.js?ver=HTML / DOM Fingerprints
acf-srf-ratingacf-srf-staracf-srf-stars-wrapperdata-field_keydata-post_iddata-vote_idsrfajaxobjectL10n/wp-json/acf-starrating/v1/settings