ACF-VC Integrator Security & Risk Analysis

wordpress.org/plugins/acf-vc-integrator

ACF-VC Plugin puts a ACF element into your WPBakery Page Builder making it easier than ever to use your custom created fields in your own page design.

3K active installs v1.8.7 PHP + WP 4.4.0+ Updated Feb 3, 2025
acfadvanced-custom-fieldsgrid-buildertemplaterawpbakery-page-builder
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ACF-VC Integrator Safe to Use in 2026?

Generally Safe

Score 92/100

ACF-VC Integrator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'acf-vc-integrator' plugin v1.8.7 exhibits a seemingly robust security posture based on the provided static analysis. The absence of identified dangerous functions, raw SQL queries, file operations, external HTTP requests, and taint flows is a significant positive indicator. Furthermore, the lack of recorded vulnerabilities in its history suggests a history of secure development or effective patching. However, the analysis reveals a critical weakness in output escaping, with only 9% of outputs being properly escaped. This significantly increases the risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data could be injected into the frontend without proper sanitization. The complete absence of nonce and capability checks across all entry points (even though there are zero identified entry points) is also a concern; if any entry points were to be discovered or introduced in future versions without these checks, the plugin would be highly vulnerable.

Key Concerns

  • Low percentage of properly escaped outputs
  • Absence of nonce checks
  • Absence of capability checks
Vulnerabilities
None known

ACF-VC Integrator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ACF-VC Integrator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
134
14 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

9% escaped148 total outputs
Attack Surface

ACF-VC Integrator Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 21
actioninitacf-vc-integrator.php:85
actionadmin_noticesacf-vc-integrator.php:117
actionadmin_initacf-vc-integrator.php:121
actionadmin_enqueue_scriptsacf-vc-integrator.php:145
actionadmin_menuacf-vc-integrator.php:150
actionvc_before_initacf-vc-integrator.php:155
filtervc_edit_form_fields_render_field_acfvc_wpbakery_hidden_field_name_beforeacf-vc-integrator.php:170
filtervc_edit_form_fields_render_field_acfvc_wpbakery_hidden_field_name_afteracf-vc-integrator.php:171
filtervc_grid_item_shortcodesacf-vc-integrator.php:176
actionadmin_initadmin\acf-vc-integrator-admin.php:532
filteracf_vc_repeater_add_on_fieldsinc\acf_vc_helper_pro.php:333
filteracf_vc_flexible_content_add_on_fieldsinc\acf_vc_helper_pro.php:334
filteracf_vc_clone_add_on_fieldsinc\acf_vc_helper_pro.php:335
filteracf_vc_add_on_fieldsinc\acf_vc_helper_pro.php:362
actionacf_vc_add_to_filter_hook_guideinc\acf_vc_helper_pro.php:388
actionacf_vc_add_to_filter_hook_guideinc\acf_vc_helper_pro.php:412
actionacf_vc_add_to_filter_hook_guideinc\acf_vc_helper_pro.php:436
actionacf_vc_add_to_filter_hook_guideinc\acf_vc_helper_pro.php:460
actionacf_vc_add_to_filter_hook_guideinc\acf_vc_helper_pro.php:484
actionacf_vc_add_to_filter_hook_guideinc\acf_vc_helper_pro.php:528
filtervc_gitem_template_attribute_acfvcinc\wpbakery\wpbakery_grid_element_attributes.php:296
Maintenance & Trust

ACF-VC Integrator Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedFeb 3, 2025
PHP min version
Downloads74K

Community Trust

Rating98/100
Number of ratings19
Active installs3K
Developer Profile

ACF-VC Integrator Developer Profile

Kåre Mulvad Steffensen

1 plugin · 3K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ACF-VC Integrator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/acf-vc-integrator/css/admin-style.css
Script Paths
/wp-content/plugins/acf-vc-integrator/inc/wpbakery/acfvc_hidden_field.js

HTML / DOM Fingerprints

CSS Classes
acfvc_hidden-fieldvc_edit-form-hidden-field-wrapper
Data Attributes
data-vc-shortcode="acf_vc_integrator"
JS Globals
ACFVC_URL
Shortcode Output
<!-- ACF-VC Integrator -->
FAQ

Frequently Asked Questions about ACF-VC Integrator