
Table Field Add-on for ACF and SCF Security & Risk Analysis
wordpress.org/plugins/advanced-custom-fields-table-fieldA Table Field Add-on for the Advanced Custom Fields and Secure Custom Fields Plugin.
Is Table Field Add-on for ACF and SCF Safe to Use in 2026?
Generally Safe
Score 98/100Table Field Add-on for ACF and SCF has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of 'advanced-custom-fields-table-field' v1.3.34 reveals a generally good security posture with no identified dangerous functions, SQL injection vulnerabilities, or file operations. The absence of exposed AJAX handlers, REST API routes, shortcodes, and cron events indicates a limited attack surface. Furthermore, 100% of SQL queries utilize prepared statements and the majority of output is properly escaped, suggesting developers have implemented some fundamental security practices. However, the vulnerability history is a significant concern. The plugin has a record of two known medium-severity CVEs, both related to Cross-Site Scripting. While there are currently no unpatched vulnerabilities, the existence of past XSS flaws, especially with the last one being recent (2026-01-05), suggests a recurring pattern of input sanitization issues. The lack of nonce checks and capability checks in the code signals, despite a zero attack surface, implies that if any entry points were to be introduced or discovered, they might lack crucial authorization mechanisms. In conclusion, while the current code analysis shows strengths in preventing common vulnerabilities like SQL injection, the historical pattern of XSS flaws warrants caution and suggests that thorough auditing for input sanitization remains essential.
Key Concerns
- Known medium CVEs with XSS history
- Lack of nonce checks
- Lack of capability checks
- Some output not properly escaped
Table Field Add-on for ACF and SCF Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Table Field Add-on for ACF and SCF <= 1.3.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via Table Cell Content
Advanced Custom Fields: Table Field < 1.1.13 - Authenticated Stored Cross-Site Scripting
Table Field Add-on for ACF and SCF Code Analysis
Output Escaping
Table Field Add-on for ACF and SCF Attack Surface
WordPress Hooks 4
Maintenance & Trust
Table Field Add-on for ACF and SCF Maintenance & Trust
Maintenance Signals
Community Trust
Table Field Add-on for ACF and SCF Alternatives
ACF: TablePress
acf-tablepress
ACF field type to select a TablePress table
ACF Content Analysis for Yoast SEO
acf-content-analysis-for-yoast-seo
WordPress plugin that adds the content of all ACF fields to the Yoast SEO score analysis.
Advanced Custom Fields: Font Awesome Field
advanced-custom-fields-font-awesome
Adds a new 'Font Awesome Icon' field to the popular Advanced Custom Fields plugin.
ACF: Better Search
acf-better-search
This plugin adds to default WordPress search engine the ability to search by content from selected fields of Advanced Custom Fields plugin.
WP All Import – Import Add-On for ACF
csv-xml-import-for-acf
Drag & drop to import any CSV, Excel, XML, or Google Sheets file into Advanced Custom Fields. Supports repeaters, flexible content, galleries, and …
Table Field Add-on for ACF and SCF Developer Profile
2 plugins · 51K total installs
How We Detect Table Field Add-on for ACF and SCF
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-custom-fields-table-field/assets/css/acf-table-field.css/wp-content/plugins/advanced-custom-fields-table-field/assets/js/acf-table-field.js/wp-content/plugins/advanced-custom-fields-table-field/assets/js/acf-table-field.jsadvanced-custom-fields-table-field/assets/css/acf-table-field.css?ver=advanced-custom-fields-table-field/assets/js/acf-table-field.js?ver=HTML / DOM Fingerprints
acf-table-rootacf-table-optionwrapacf-table-optionboxacf-table-optionbox-fieldacf-table-fc-opt-use-headeracf-table-fc-opt-caption<!-- OPTION HEADER { --><!-- } --><!-- OPTION CAPTION { --><!-- } -->data-use-headerdata-use-captionacf.add_filter('validation_success', function( data ) {acf.add_action('append', function( $el ) {acf.add_action('ready', function( $el ) {acf.add_action('remove', function( $el ) {