
ACF YouTube Picker Security & Risk Analysis
wordpress.org/plugins/acf-youtube-pickerSearch and select videos on YouTube without leaving the page.
Is ACF YouTube Picker Safe to Use in 2026?
Generally Safe
Score 85/100ACF YouTube Picker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The acf-youtube-picker v3.1.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points significantly reduces its attack surface. Furthermore, the code analysis shows no dangerous functions, all SQL queries utilize prepared statements, and the vast majority of output is properly escaped. The lack of any historical CVEs further reinforces this positive outlook, suggesting a mature and well-maintained codebase regarding security.
However, a few areas warrant attention. The presence of a file operation, even if only one, combined with the complete absence of nonce checks and capability checks, raises a slight concern. While the static analysis found no specific vulnerabilities in these areas, these are common mechanisms for securing WordPress functionalities. The taint analysis revealing zero flows with unsanitized paths is excellent, but the lack of nonce and capability checks means that if a vulnerability were introduced in the future, it might be more easily exploitable.
In conclusion, acf-youtube-picker v3.1.0 appears to be a secure plugin with a minimal attack surface and excellent practices regarding SQL and output escaping. The complete absence of vulnerabilities in its history is a significant strength. The primary area for potential improvement lies in implementing nonce and capability checks for its file operations to further bolster its security and adhere to best practices, even in the absence of immediate exploitable flaws.
Key Concerns
- File operations present without capability checks
- File operations present without nonce checks
ACF YouTube Picker Security Vulnerabilities
ACF YouTube Picker Release Timeline
ACF YouTube Picker Code Analysis
Output Escaping
ACF YouTube Picker Attack Surface
WordPress Hooks 2
Maintenance & Trust
ACF YouTube Picker Maintenance & Trust
Maintenance Signals
Community Trust
ACF YouTube Picker Alternatives
ACF: Better Search
acf-better-search
This plugin adds to default WordPress search engine the ability to search by content from selected fields of Advanced Custom Fields plugin.
Date and Time Picker Field
acf-field-date-time-picker
Date and Time Picker field for Advanced Custom Fields
ACF Color Swatches
acf-color-swatches
An add-on for Advanced Custom Fields to allow users to select from a list of color choices. Setting up the field works exactly like setting up a radio …
Date & Time Picker for Advanced Custom Fields
acf-date-time-picker
Date & Time Picker field for Advanced Custom Fields 4 and 5.
ACF Google Maps Radius Search
acf-google-maps-radius-search
Turns ACF address field into a distance radius search on a search results page. Useful for developers.
ACF YouTube Picker Developer Profile
2 plugins · 700 total installs
How We Detect ACF YouTube Picker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/acf-youtube-picker/css/acf-youtubepicker-field.css/wp-content/plugins/acf-youtube-picker/js/acf-youtubepicker-field.js/wp-content/plugins/acf-youtube-picker/js/acf-youtubepicker-field.jsacf-youtubepicker/css/acf-youtubepicker-field.css?ver=acf-youtubepicker/js/acf-youtubepicker-field.js?ver=HTML / DOM Fingerprints
acf-youtubepicker-wrapyp-advanced-optionsdata-field_iddata-api_keydata-channelIddata-channelTypedata-eventTypedata-order+15 moreacf_youtubepicker_field