
Advanced Custom Fields: Sites Field Security & Risk Analysis
wordpress.org/plugins/advanced-custom-fields-sites-fieldAdds a sites field type to ACF. Allows for selection of one or multiple sites in a multisite network.
Is Advanced Custom Fields: Sites Field Safe to Use in 2026?
Generally Safe
Score 85/100Advanced Custom Fields: Sites Field has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "advanced-custom-fields-sites-field" v2.0.0 demonstrates a generally positive security posture based on the provided static analysis and vulnerability history. The absence of identified CVEs, critical taint flows, and raw SQL queries suggests a mature development process that prioritizes secure coding practices. The zero attack surface and zero unsanitized flows are particularly encouraging, indicating that entry points into the plugin are either nonexistent or well-protected.
However, a significant concern arises from the output escaping results. With 31 total outputs and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any data that is displayed to users, especially if it originates from user input or external sources, is not being properly sanitized before rendering. This could allow malicious actors to inject scripts that execute in the context of a user's browser, potentially leading to session hijacking, data theft, or defacement.
The lack of any capability checks, nonce checks, and the absence of AJAX handlers or REST API routes (even unprotected ones) are neutral findings. While the absence of unprotected entry points is good, the complete lack of security checks across all potential interaction points could be interpreted as either a sign of extreme simplicity or a potential oversight where such checks might be implicitly expected if the plugin were to evolve. The vulnerability history being entirely clear is a strong positive, suggesting a history of secure development.
Key Concerns
- No output escaping detected
Advanced Custom Fields: Sites Field Security Vulnerabilities
Advanced Custom Fields: Sites Field Code Analysis
Output Escaping
Advanced Custom Fields: Sites Field Attack Surface
WordPress Hooks 2
Maintenance & Trust
Advanced Custom Fields: Sites Field Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Custom Fields: Sites Field Alternatives
Sort My Sites
sort-my-sites
Sort My Sites lets you change the ordering of the My Sites menu on the dashboard and in the admin bar.
NGO-menu-deactivate
ngo-menu-deactivate
License GPLv3 License URI: http://www.gnu.org/licenses/gpl-3.0.html Cleans up WordPress admin for sites and simplifying it disabling menues not neede …
Sitelets for Multisite – Local Pages & Content Management for WordPress Multisite
sitelets-for-multisite
Easily create, customize & update local pages across all sites in your WordPress Multisite network — ideal for franchises & multi-location SEO
ACF Content Analysis for Yoast SEO
acf-content-analysis-for-yoast-seo
WordPress plugin that adds the content of all ACF fields to the Yoast SEO score analysis.
Advanced Custom Fields: Font Awesome Field
advanced-custom-fields-font-awesome
Adds a new 'Font Awesome Icon' field to the popular Advanced Custom Fields plugin.
Advanced Custom Fields: Sites Field Developer Profile
1 plugin · 40 total installs
How We Detect Advanced Custom Fields: Sites Field
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-custom-fields-sites-field/css/acf-sites-field.css/wp-content/plugins/advanced-custom-fields-sites-field/js/acf-sites-field.js/wp-content/plugins/advanced-custom-fields-sites-field/js/acf-sites-field.jsadvanced-custom-fields-sites-field/css/acf-sites-field.css?ver=advanced-custom-fields-sites-field/js/acf-sites-field.js?ver=HTML / DOM Fingerprints
acf-sites-fieldacf-sohdata-type