
Advanced Custom Fields: NextGen Gallery Custom Field Security & Risk Analysis
wordpress.org/plugins/advanced-custom-fields-nextgen-gallery-custom-fieldThis plugin provides an extra field for the Advanced Custom Fields plugin to support the NextGEN Gallery plugin.
Is Advanced Custom Fields: NextGen Gallery Custom Field Safe to Use in 2026?
Generally Safe
Score 85/100Advanced Custom Fields: NextGen Gallery Custom Field has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'advanced-custom-fields-nextgen-gallery-custom-field' version 1.1.4 exhibits a mixed security posture. On the positive side, the static analysis reveals a clean slate regarding dangerous functions, SQL injection vulnerabilities (all queries are prepared), file operations, external HTTP requests, and a complete absence of known CVEs. This indicates a generally cautious approach to certain common attack vectors. However, a significant concern arises from the complete lack of output escaping for all 12 identified output points. This means that any data rendered to the user could potentially contain malicious scripts or code, leading to cross-site scripting (XSS) vulnerabilities. Furthermore, the absence of nonce checks and capability checks, especially given the lack of authentication checks on AJAX handlers (though there are none currently), could become a weakness if new entry points are introduced in the future without proper security measures. The lack of recorded vulnerabilities historically is a positive sign, but it does not negate the immediate risks identified in the code analysis.
Key Concerns
- 0% output escaping
- 0 nonce checks
- 0 capability checks
Advanced Custom Fields: NextGen Gallery Custom Field Security Vulnerabilities
Advanced Custom Fields: NextGen Gallery Custom Field Code Analysis
Output Escaping
Advanced Custom Fields: NextGen Gallery Custom Field Attack Surface
WordPress Hooks 2
Maintenance & Trust
Advanced Custom Fields: NextGen Gallery Custom Field Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Custom Fields: NextGen Gallery Custom Field Alternatives
ACF Content Analysis for Yoast SEO
acf-content-analysis-for-yoast-seo
WordPress plugin that adds the content of all ACF fields to the Yoast SEO score analysis.
Advanced Custom Fields: Font Awesome Field
advanced-custom-fields-font-awesome
Adds a new 'Font Awesome Icon' field to the popular Advanced Custom Fields plugin.
Table Field Add-on for ACF and SCF
advanced-custom-fields-table-field
A Table Field Add-on for the Advanced Custom Fields and Secure Custom Fields Plugin.
ACF: Better Search
acf-better-search
This plugin adds to default WordPress search engine the ability to search by content from selected fields of Advanced Custom Fields plugin.
WP All Import – Import Add-On for ACF
csv-xml-import-for-acf
Drag & drop to import any CSV, Excel, XML, or Google Sheets file into Advanced Custom Fields. Supports repeaters, flexible content, galleries, and …
Advanced Custom Fields: NextGen Gallery Custom Field Developer Profile
1 plugin · 200 total installs
How We Detect Advanced Custom Fields: NextGen Gallery Custom Field
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-custom-fields-nextgen-gallery-custom-field/nggallery-v4.php