
Advanced Custom Fields: Multiple Coordinates Security & Risk Analysis
wordpress.org/plugins/advanced-custom-fields-multiple-coordinatesThis is an add-on to ACF that adds a field to select multiple Google Map points in a post.
Is Advanced Custom Fields: Multiple Coordinates Safe to Use in 2026?
Generally Safe
Score 85/100Advanced Custom Fields: Multiple Coordinates has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "advanced-custom-fields-multiple-coordinates" plugin v1.0.2 indicates a generally good security posture. There are no identified critical or high-severity vulnerabilities in the code, and the plugin exhibits good practices such as using prepared statements for all SQL queries and a high percentage of properly escaped output. The absence of dangerous functions, file operations, external HTTP requests, and the lack of a significant attack surface are positive indicators.
However, a notable concern is the complete lack of nonce checks and capability checks. This suggests that any potential entry points, if they were to exist or be introduced in future versions, would be susceptible to cross-site request forgery (CSRF) and unauthorized access without proper authorization validation. The taint analysis also revealed no flows, which could be due to a very simple codebase or potentially insufficient analysis for certain complex scenarios. The vulnerability history is clean, with no recorded CVEs, which is a strong positive, but this should not be a reason to neglect essential security checks.
In conclusion, while the current version of the plugin appears robust against common attack vectors due to its clean code and lack of known vulnerabilities, the absence of nonce and capability checks presents a significant oversight. This could lead to vulnerabilities if the plugin's functionality expands or if previously undiscovered entry points are identified. Developers should prioritize implementing these essential security measures to harden the plugin against potential future threats.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Low percentage of escaped output (11% unescaped)
Advanced Custom Fields: Multiple Coordinates Security Vulnerabilities
Advanced Custom Fields: Multiple Coordinates Code Analysis
Output Escaping
Advanced Custom Fields: Multiple Coordinates Attack Surface
WordPress Hooks 1
Maintenance & Trust
Advanced Custom Fields: Multiple Coordinates Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Custom Fields: Multiple Coordinates Alternatives
ACF qTranslate
acf-qtranslate
Provides qTranslate compatible ACF field types for Text, Text Area, WYSIWYG, Image and File.
Admin Columns for ACF Fields
admin-columns-for-acf-fields
Allows you to enable columns for your ACF fields in post and taxonomy overviews (e.g. "All Posts") in the Wordpress admin backend.
Advanced Custom Fields: Typography Field
acf-typography-field
A Typography Add-on for the Advanced Custom Fields Plugin.
ACF: Google Map Extended
advanced-custom-fields-google-map-extended
ACF field. Saves map center, zoom level. Disables map zooming on scroll. Shows location coordinates. Bonus for programmers.
whatwedo ACF Cleaner
whatwedo-acf-cleaner
Cleanup old metadata created by Advanced Custom Fields.
Advanced Custom Fields: Multiple Coordinates Developer Profile
3 plugins · 660 total installs
How We Detect Advanced Custom Fields: Multiple Coordinates
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-custom-fields-multiple-coordinates/css/fields.css/wp-content/plugins/advanced-custom-fields-multiple-coordinates/js/map.js//maps.googleapis.com/maps/api/js?sensor=falseadvanced-custom-fields-multiple-coordinates/css/fields.css?ver=advanced-custom-fields-multiple-coordinates/js/map.js?ver=HTML / DOM Fingerprints
location_multiple_coordinates_input_searchlocation_multiple_coordinates_addlocation_multiple_coordinates_removelocation_multiple_coordinates_show_arealocation_multiple_coordinates_coordinates_buttonlocation_multiple_coordinates_values_buttonlocation_multiple_coordinates_valueslocation_multiple_coordinates_coordinates_div+2 moredata-name="location_multiple_coordinates_input_search"data-name="location_multiple_coordinates_add"data-name="location_multiple_coordinates_remove"data-name="location_multiple_coordinates_show_area"data-name="location_multiple_coordinates_coordinates_button"data-name="location_multiple_coordinates_values_button"+4 moregooglemaps-apiacf-multiple-coordinates-map