
Advanced Custom Fields: oEmbed Field Security & Risk Analysis
wordpress.org/plugins/advanced-custom-fields-oembed-fieldAdds an oEmbed field type to Advanced Custom Fields.
Is Advanced Custom Fields: oEmbed Field Safe to Use in 2026?
Generally Safe
Score 85/100Advanced Custom Fields: oEmbed Field has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "advanced-custom-fields-oembed-field" plugin version 1.0.3 exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices by exclusively using prepared statements for SQL queries and avoids dangerous functions, file operations, and external HTTP requests. The absence of any recorded vulnerabilities or CVEs in its history is also a positive indicator of its past security diligence.
However, significant concerns arise from the static analysis. The plugin exposes a single AJAX handler that lacks any authentication or capability checks. This unprotected entry point represents a critical weakness, as it could potentially be exploited by unauthenticated users to perform unintended actions or trigger unexpected behavior. The lack of nonce checks further exacerbates this issue, leaving it vulnerable to Cross-Site Request Forgery (CSRF) attacks.
While the plugin has a clean vulnerability history, the presence of an unprotected AJAX endpoint is a serious oversight that overshadows this positive aspect. The complete absence of taint analysis flows is also noted, which might indicate limited testing in this area or a very simple plugin structure. The plugin's strengths lie in its database query and output handling, but the critical flaw in its AJAX endpoint security requires immediate attention.
Key Concerns
- Unprotected AJAX handler without auth checks
- Missing nonce checks on AJAX entry points
- Low percentage of properly escaped output
Advanced Custom Fields: oEmbed Field Security Vulnerabilities
Advanced Custom Fields: oEmbed Field Code Analysis
Output Escaping
Advanced Custom Fields: oEmbed Field Attack Surface
AJAX Handlers 1
WordPress Hooks 2
Maintenance & Trust
Advanced Custom Fields: oEmbed Field Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Custom Fields: oEmbed Field Alternatives
ACF Content Analysis for Yoast SEO
acf-content-analysis-for-yoast-seo
WordPress plugin that adds the content of all ACF fields to the Yoast SEO score analysis.
Advanced Custom Fields: Font Awesome Field
advanced-custom-fields-font-awesome
Adds a new 'Font Awesome Icon' field to the popular Advanced Custom Fields plugin.
Table Field Add-on for ACF and SCF
advanced-custom-fields-table-field
A Table Field Add-on for the Advanced Custom Fields and Secure Custom Fields Plugin.
ACF: Better Search
acf-better-search
This plugin adds to default WordPress search engine the ability to search by content from selected fields of Advanced Custom Fields plugin.
WP All Import – Import Add-On for ACF
csv-xml-import-for-acf
Drag & drop to import any CSV, Excel, XML, or Google Sheets file into Advanced Custom Fields. Supports repeaters, flexible content, galleries, and …
Advanced Custom Fields: oEmbed Field Developer Profile
2 plugins · 1K total installs
How We Detect Advanced Custom Fields: oEmbed Field
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-custom-fields-oembed-field/oembed-v3.php/wp-content/plugins/advanced-custom-fields-oembed-field/oembed-v4.php/wp-content/plugins/advanced-custom-fields-oembed-field/js/input.jsadvanced-custom-fields-oembed-field/js/input.js?ver=advanced-custom-fields-oembed-field/css/input.css?ver=HTML / DOM Fingerprints
acf-field-oembeddata-preview_sizeacf_oembed_ajax/wp-json/acf/v1/oembed