Advanced Custom Fields: W4 Post List Bridge Security & Risk Analysis

wordpress.org/plugins/advanced-custom-fields-w4-post-list-bridge

This plugin provides a [post_field field="field-name"] shortcode connecting an Advanced Custom Fields field to your W4 Post List list templa …

70 active installs v1.0.0 PHP + WP 3.0.0+ Updated Jul 17, 2015
acfcustom-post-listpost-listshortcode
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Advanced Custom Fields: W4 Post List Bridge Safe to Use in 2026?

Generally Safe

Score 85/100

Advanced Custom Fields: W4 Post List Bridge has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

This plugin exhibits an excellent security posture based on the provided static analysis. The absence of any identified dangerous functions, unsanitized taint flows, direct SQL queries, or unescaped output indicates strong adherence to secure coding practices. The plugin also has a clean vulnerability history, with no known CVEs recorded, which further bolsters its security reputation. The lack of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface, and crucially, all identified entry points (if any existed) are protected by authorization checks.

While the static analysis results are overwhelmingly positive, the complete absence of certain checks like nonce checks and capability checks on entry points might be a result of the plugin having no such entry points to begin with, or it could indicate a potential oversight if future versions introduce such features without corresponding security measures. However, based on the current data, there are no immediate security concerns or exploitable vulnerabilities. The plugin appears well-developed from a security perspective.

Vulnerabilities
None known

Advanced Custom Fields: W4 Post List Bridge Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Advanced Custom Fields: W4 Post List Bridge Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Advanced Custom Fields: W4 Post List Bridge Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filterw4pl/get_shortcodesacf-w4-post-list-bridge.php:13
Maintenance & Trust

Advanced Custom Fields: W4 Post List Bridge Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedJul 17, 2015
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs70
Developer Profile

Advanced Custom Fields: W4 Post List Bridge Developer Profile

pmill

1 plugin · 70 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Advanced Custom Fields: W4 Post List Bridge

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/advanced-custom-fields-w4-post-list-bridge/acf-w4-post-list-bridge.php

HTML / DOM Fingerprints

Shortcode Output
[post_field field="field-name"]
FAQ

Frequently Asked Questions about Advanced Custom Fields: W4 Post List Bridge