
ACF WPML Theme Options Security & Risk Analysis
wordpress.org/plugins/acf-wpml-theme-optionsPlugin which adds another way of displaying global options created with ACF on websites which use WPML for multilanguage purposes.
Is ACF WPML Theme Options Safe to Use in 2026?
Generally Safe
Score 85/100ACF WPML Theme Options has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "acf-wpml-theme-options" v1.0.0 plugin exhibits a concerning security posture despite a clean vulnerability history and a limited attack surface. While it boasts no AJAX handlers, REST API routes, cron events, or external HTTP requests, and has only one shortcode entry point, the code analysis reveals significant weaknesses. The presence of `unserialize` is a major red flag, especially without any evident nonce or capability checks. Furthermore, all SQL queries are executed without prepared statements, and a substantial number of output variables are not properly escaped. The taint analysis, while not flagging critical or high-severity issues in this specific run, highlights flows with unsanitized paths, which, when combined with the other identified weaknesses, creates a potentially exploitable environment. The lack of any recorded vulnerabilities in its history could indicate a lack of prior auditing or a very new plugin, rather than inherent security. Overall, the plugin has critical flaws in data handling and execution that outweigh its minimal attack surface and clean history, demanding immediate attention.
Key Concerns
- Dangerous unserialize function found
- SQL queries lack prepared statements
- Output escaping is not properly implemented
- No nonce checks present
- No capability checks present
- Taint flows with unsanitized paths
ACF WPML Theme Options Security Vulnerabilities
ACF WPML Theme Options Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
ACF WPML Theme Options Attack Surface
Shortcodes 1
WordPress Hooks 15
Maintenance & Trust
ACF WPML Theme Options Maintenance & Trust
Maintenance Signals
Community Trust
ACF WPML Theme Options Alternatives
One Click Demo Import
one-click-demo-import
Import your demo content, widgets and theme settings with one click. Theme authors! Enable simple theme demo import for your users.
OptionTree
option-tree
Theme Options UI Builder for WordPress. A simple way to create & save Theme Options and Meta Boxes for free or premium themes.
Import / Export Customizer Settings
astra-import-export
Astra theme customizer offers several settings for header/footer layout, sidebar and blog designs, colors, backgrounds, typography and much more.
ACF RGBA Color Picker
acf-rgba-color-picker
A RGBA-Color-Picker field for Advanced Custom Fields
Catch Themes Demo Import
catch-themes-demo-import
Catch Themes Demo Import is a simple and easy-to-use demo importer WordPress plugin that allows you to import the theme demo data Based on One Click D …
ACF WPML Theme Options Developer Profile
3 plugins · 2K total installs
How We Detect ACF WPML Theme Options
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/acf-wpml-theme-options/admin/assets/css/acf-wpml-theme-options.css/wp-content/plugins/acf-wpml-theme-options/admin/assets/js/acf-wpml-settings.js/wp-content/plugins/acf-wpml-theme-options/admin/assets/js/set-acf-wpml-post-active.js//malsup.github.io/jquery.blockUI.jsacf-wpml-theme-options.css?ver=acf-wpml-settings.js?ver=set-acf-wpml-post-active.js?ver=HTML / DOM Fingerprints
acf-wpml-to-activeacf-wpml-to-active-linkacf-wpml-to-active-icon<!-- The plugin cannot be used when both ACF and ACF Pro are active --><!-- Fire! --><!-- Main function --><!-- Shortcode version -->+3 moredata-post-iddata-ajax-urlpostactive[get_field_option