Advanced Custom Fields: Nav Menu Field Security & Risk Analysis

wordpress.org/plugins/advanced-custom-fields-nav-menu-field

Add-On plugin for Advanced Custom Fields (ACF) that adds a 'Nav Menu' Field type.

9K active installs v2.0.0 PHP + WP 3.4+ Updated Nov 28, 2017
acfacf4acf5advanced-custom-fieldscustom-fields
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Advanced Custom Fields: Nav Menu Field Safe to Use in 2026?

Generally Safe

Score 85/100

Advanced Custom Fields: Nav Menu Field has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The static analysis of advanced-custom-fields-nav-menu-field v2.0.0 reveals a strong security posture. The absence of any detected dangerous functions, unsanitized taint flows, raw SQL queries, or file operations is commendable. The fact that all SQL queries utilize prepared statements and all output is properly escaped demonstrates adherence to secure coding best practices.

However, the analysis also highlights a complete lack of security checks, including nonce checks and capability checks, across all identified entry points (though there are none detected in this version). This might indicate either a very limited functionality that doesn't require these checks, or a potential oversight if functionality is added in the future without corresponding security measures. The vulnerability history is clean, with no recorded CVEs, which is a positive indicator of the plugin's historical security maintenance.

In conclusion, the plugin appears secure in its current state based on the provided data. Its strengths lie in its clean code regarding dangerous functions, SQL, and output escaping. The primary weakness, or rather a point of caution, is the complete absence of any authentication or authorization checks, which, while not currently exploitable due to the zero attack surface, could become a concern if the plugin evolves. The spotless vulnerability history is a significant positive, suggesting responsible development and maintenance.

Key Concerns

  • No capability checks found
  • No nonce checks found
Vulnerabilities
None known

Advanced Custom Fields: Nav Menu Field Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Advanced Custom Fields: Nav Menu Field Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
24 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped24 total outputs
Attack Surface

Advanced Custom Fields: Nav Menu Field Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionacf/register_fieldsfz-acf-nav-menu.php:24
actionacf/include_field_typesfz-acf-nav-menu.php:27
Maintenance & Trust

Advanced Custom Fields: Nav Menu Field Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedNov 28, 2017
PHP min version
Downloads134K

Community Trust

Rating100/100
Number of ratings33
Active installs9K
Developer Profile

Advanced Custom Fields: Nav Menu Field Developer Profile

Faison

3 plugins · 9K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Advanced Custom Fields: Nav Menu Field

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/advanced-custom-fields-nav-menu-field/nav-menu-v4.php/wp-content/plugins/advanced-custom-fields-nav-menu-field/nav-menu-v5.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Advanced Custom Fields: Nav Menu Field