Advanced Custom Field: Shortcode Field Security & Risk Analysis

wordpress.org/plugins/advanced-custom-fields-shortcode-field

When you enter a shortcode, it will be executed and outputted, by using the_field('FIELD_NAME_HERE') in your theme.

200 active installs v4.0 PHP + WP 3.4+ Updated Jun 29, 2013
custom-fieldsshortcode
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Advanced Custom Field: Shortcode Field Safe to Use in 2026?

Generally Safe

Score 85/100

Advanced Custom Field: Shortcode Field has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The plugin 'advanced-custom-fields-shortcode-field' v4.0 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any identified dangerous functions, SQL queries without prepared statements, and a high percentage of properly escaped output are significant strengths. The plugin also shows no file operations or external HTTP requests, which further reduces its attack surface and potential for compromise. The lack of known CVEs and a clean vulnerability history indicate a commitment to security or a lack of discovered vulnerabilities, both positive signs.

However, the complete absence of nonce checks and capability checks, combined with zero identified entry points through AJAX, REST API, or shortcodes, raises a slight concern. While no vulnerabilities are currently evident, this lack of standard security checks means that if any entry points were to be introduced or discovered in future versions, they might be vulnerable by default. The static analysis did not find any taint flows, but this is contingent on the analysis being comprehensive and covering all potential paths. Overall, the plugin appears robust and secure currently, but the absence of fundamental security checks warrants a minor deduction as a precautionary measure.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Advanced Custom Field: Shortcode Field Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Advanced Custom Field: Shortcode Field Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
25 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

93% escaped27 total outputs
Attack Surface

Advanced Custom Field: Shortcode Field Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionplugins_loadedinit.php:15
actionacf/register_fieldsinit.php:17
Maintenance & Trust

Advanced Custom Field: Shortcode Field Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedJun 29, 2013
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs200
Developer Profile

Advanced Custom Field: Shortcode Field Developer Profile

水野史土

11 plugins · 8K total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Advanced Custom Field: Shortcode Field

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/advanced-custom-fields-shortcode-field/js/acf-shortcode-field.js/wp-content/plugins/advanced-custom-fields-shortcode-field/css/acf-shortcode-field.css
Script Paths
/wp-content/plugins/advanced-custom-fields-shortcode-field/js/acf-shortcode-field.js
Version Parameters
advanced-custom-fields-shortcode-field/js/acf-shortcode-field.js?ver=advanced-custom-fields-shortcode-field/css/acf-shortcode-field.css?ver=

HTML / DOM Fingerprints

CSS Classes
acf-shortcode-field
FAQ

Frequently Asked Questions about Advanced Custom Field: Shortcode Field