
ACF viewer for WooCommerce Security & Risk Analysis
wordpress.org/plugins/acf-viewer-for-woocommerceAdvanced Custom Fields viewer for WooCommerce
Is ACF viewer for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100ACF viewer for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'acf-viewer-for-woocommerce' v1.0.1 plugin exhibits a generally strong security posture based on the provided static analysis. It effectively utilizes prepared statements for all SQL queries and demonstrates a high percentage of properly escaped output, mitigating common risks like SQL injection and Cross-Site Scripting (XSS). The presence of nonce checks and capability checks on entry points further strengthens its defenses. The complete absence of known vulnerabilities in its history is also a positive indicator of responsible development.
However, a notable concern is the presence of the `unserialize` function. While there are no directly observable taint flows indicating immediate risk from this function in the analyzed code, `unserialize` is inherently dangerous as it can lead to Remote Code Execution (RCE) or other vulnerabilities if used with untrusted input. The limited number of analyzed flows and the absence of documented past vulnerabilities don't entirely negate this potential risk. The attack surface is small and appears to be protected, but the underlying danger of `unserialize` warrants caution.
In conclusion, the plugin follows many good security practices, particularly in its handling of database queries and output. The lack of historical vulnerabilities is reassuring. The primary weakness lies in the potential risk associated with `unserialize`, which, despite not being actively exploited in the current analysis, represents a significant theoretical attack vector. Further analysis of how `unserialize` is used and what data sources it processes would be beneficial.
Key Concerns
- Use of dangerous unserialize function
ACF viewer for WooCommerce Security Vulnerabilities
ACF viewer for WooCommerce Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
ACF viewer for WooCommerce Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 19
Maintenance & Trust
ACF viewer for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
ACF viewer for WooCommerce Alternatives
Advanced Custom Fields YITH WooCommerce Compare support
acf-yith-woocommerce-compare-support
Advanced Custom Fields YITH WooCommerce Compare support
POI ACF for WP
poi-acf-for-wp
Allows you to add fields to the WooCommerce Checkout and My Account pages, or display fields you setup on a Product Category, on the Archive Product p …
ACF Content Analysis for Yoast SEO
acf-content-analysis-for-yoast-seo
WordPress plugin that adds the content of all ACF fields to the Yoast SEO score analysis.
Advanced Custom Fields: Font Awesome Field
advanced-custom-fields-font-awesome
Adds a new 'Font Awesome Icon' field to the popular Advanced Custom Fields plugin.
Table Field Add-on for ACF and SCF
advanced-custom-fields-table-field
A Table Field Add-on for the Advanced Custom Fields and Secure Custom Fields Plugin.
ACF viewer for WooCommerce Developer Profile
2 plugins · 120 total installs
How We Detect ACF viewer for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/acf-viewer-for-woocommerce/include/admin.js/wp-content/plugins/acf-viewer-for-woocommerce/include/admin.css/wp-content/plugins/acf-viewer-for-woocommerce/include/style.css/wp-content/plugins/acf-viewer-for-woocommerce/include/admin.jsacf-viewer-for-woocommerce/include/admin.js?ver=acf-viewer-for-woocommerce/include/admin.css?ver=acf-viewer-for-woocommerce/include/style.css?ver=HTML / DOM Fingerprints
awv-free-noticejs-awv-tablehidden-rowline-elmnsacfv-fields-wrapper<!-- Main box fields -->data-selectedawv_data