
Advanced Custom Fields: Leaflet Field Security & Risk Analysis
wordpress.org/plugins/advanced-custom-fields-leaflet-fieldAddon for Advanced Custom Fields that adds a Leaflet field to the available field types.
Is Advanced Custom Fields: Leaflet Field Safe to Use in 2026?
Generally Safe
Score 85/100Advanced Custom Fields: Leaflet Field has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "advanced-custom-fields-leaflet-field" plugin v1.2.1, based on the provided static analysis, exhibits a generally strong security posture with no detected vulnerabilities in its history. The absence of known CVEs and the complete reliance on prepared statements for SQL queries are significant positive indicators. However, a critical concern arises from the complete lack of output escaping for all 49 detected output points. This represents a significant risk for cross-site scripting (XSS) vulnerabilities, as user-supplied data, if processed by these unescaped outputs, could be rendered directly in the browser, leading to malicious code execution.
While the plugin has no detected attack surface through AJAX, REST API, shortcodes, or cron events, and no dangerous functions, file operations, or external HTTP requests were found, the unescaped output is a glaring weakness. The zero taint analysis results are positive, suggesting no immediate exploitable flows were identified in that specific analysis method. The lack of nonce and capability checks, while not directly indicative of a vulnerability in this limited analysis scope, could become problematic if any new entry points are introduced or if the plugin interacts with sensitive data in unforeseen ways. Overall, the plugin shows good development practices in areas like SQL handling and attack surface minimization, but the complete disregard for output escaping presents a substantial risk that needs immediate attention.
Key Concerns
- Unescaped output detected on all outputs
Advanced Custom Fields: Leaflet Field Security Vulnerabilities
Advanced Custom Fields: Leaflet Field Code Analysis
Output Escaping
Advanced Custom Fields: Leaflet Field Attack Surface
WordPress Hooks 5
Maintenance & Trust
Advanced Custom Fields: Leaflet Field Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Custom Fields: Leaflet Field Alternatives
ACF qTranslate
acf-qtranslate
Provides qTranslate compatible ACF field types for Text, Text Area, WYSIWYG, Image and File.
Admin Columns for ACF Fields
admin-columns-for-acf-fields
Allows you to enable columns for your ACF fields in post and taxonomy overviews (e.g. "All Posts") in the Wordpress admin backend.
Advanced Custom Fields: Nav Menu Field
advanced-custom-fields-nav-menu-field
Add-On plugin for Advanced Custom Fields (ACF) that adds a 'Nav Menu' Field type.
Advanced Custom Fields: Typography Field
acf-typography-field
A Typography Add-on for the Advanced Custom Fields Plugin.
Advanced Custom Fields: Limiter Field
advanced-custom-fields-limiter-field
This plugin provides a textarea that limits the number of characters a user can add. The limit is cleanly represented by a jQuery UI progress bar.
Advanced Custom Fields: Leaflet Field Developer Profile
6 plugins · 270 total installs
How We Detect Advanced Custom Fields: Leaflet Field
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-custom-fields-leaflet-field/leaflet_field-v3.php/wp-content/plugins/advanced-custom-fields-leaflet-field/leaflet_field-v4.php/wp-content/plugins/advanced-custom-fields-leaflet-field/leaflet_field-v5.php/wp-content/plugins/advanced-custom-fields-leaflet-field/js/leaflet/leaflet.css/wp-content/plugins/advanced-custom-fields-leaflet-field/js/leaflet/leaflet.js/wp-content/plugins/advanced-custom-fields-leaflet-field/js/leaflet-frontend.js/wp-content/plugins/advanced-custom-fields-leaflet-field/js/leaflet-frontend.jsadvanced-custom-fields-leaflet-field/js/leaflet/leaflet.css?ver=advanced-custom-fields-leaflet-field/js/leaflet/leaflet.js?ver=advanced-custom-fields-leaflet-field/js/leaflet-frontend.js?ver=HTML / DOM Fingerprints
leaflet-mapleaflet_field