Advanced Custom Fields: Widget Security & Risk Analysis

wordpress.org/plugins/advanced-custom-fields-widget

A widget that is able to use content from an ACF field group

200 active installs v1.0.2 PHP + WP 3.0+ Updated May 9, 2016
acfadvanced-custom-fieldswidgetwidgets
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Advanced Custom Fields: Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Advanced Custom Fields: Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The 'advanced-custom-fields-widget' plugin v1.0.2 exhibits a strong security posture based on the provided static analysis. It demonstrates good practices by having no recorded vulnerabilities, a clean slate with no known CVEs, and a complete absence of critical or high severity taint flows. The code signals also show positive indicators like 100% of SQL queries using prepared statements and the presence of a nonce check, suggesting an awareness of common WordPress security pitfalls. The lack of external HTTP requests and file operations further minimizes potential attack vectors.

Key Concerns

  • Low output escaping
  • No capability checks
Vulnerabilities
None known

Advanced Custom Fields: Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Advanced Custom Fields: Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
19
3 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

14% escaped22 total outputs
Attack Surface

Advanced Custom Fields: Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionwidgets_initacf-widget.php:38
actionsidebar_admin_setupacf-widget.php:82
filteracf/location/rule_typesincludes\class-acf-widget-plugin-init.php:11
filteracf/location/rule_values/widgetincludes\class-acf-widget-plugin-init.php:12
actionsidebar_admin_setupincludes\class-acf-widget-plugin.php:10
actionadmin_enqueue_scriptsincludes\class-acf-widget-plugin.php:16
actionadmin_headincludes\class-acf-widget-plugin.php:17
actionadmin_footerincludes\class-acf-widget-plugin.php:18
Maintenance & Trust

Advanced Custom Fields: Widget Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedMay 9, 2016
PHP min version
Downloads8K

Community Trust

Rating100/100
Number of ratings1
Active installs200
Developer Profile

Advanced Custom Fields: Widget Developer Profile

alexvandervegt

2 plugins · 210 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Advanced Custom Fields: Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/advanced-custom-fields-widget/acf-widget.js
Version Parameters
advanced-custom-fields-widget/acf-widget.js?ver=acf-widget.js?ver=

HTML / DOM Fingerprints

CSS Classes
acf_widget
Data Attributes
data-layoutdata-show
JS Globals
jQuery
FAQ

Frequently Asked Questions about Advanced Custom Fields: Widget