
Advanced Custom Fields – Widget Relationship Field add-on Security & Risk Analysis
wordpress.org/plugins/advanced-custom-fields-widget-relationship-field-add-onThis plugin is an add-on for Advanced Custom Fields. It allows you to use an ACF "relationship" field to choose widgets at a page level.
Is Advanced Custom Fields – Widget Relationship Field add-on Safe to Use in 2026?
Generally Safe
Score 85/100Advanced Custom Fields – Widget Relationship Field add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The advanced-custom-fields-widget-relationship-field-add-on plugin v1.3.4 exhibits a generally strong security posture based on the static analysis. The absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and file operations is commendable. Furthermore, the plugin correctly implements nonce checks and avoids external HTTP requests, minimizing common attack vectors. The attack surface, while present with two AJAX handlers, is reported as having no unprotected entry points, which is a significant positive signal.
However, a primary concern arises from the output escaping analysis. With 33% of outputs properly escaped out of 12 total, this indicates that a significant portion (67%) of the plugin's output might be vulnerable to cross-site scripting (XSS) attacks. While taint analysis shows no unsanitized paths, the lack of robust output sanitization on nearly all observed outputs is a notable weakness. The vulnerability history being clear of any known CVEs is a positive indicator, suggesting a history of responsible development, but it doesn't mitigate the potential for undiscovered vulnerabilities, especially in the identified output escaping gaps.
In conclusion, the plugin demonstrates good development practices in areas like SQL handling and authentication. The absence of historical vulnerabilities is a strong point. Nevertheless, the widespread issue with output escaping presents a clear and present risk of XSS vulnerabilities that needs to be addressed to consider the plugin truly secure.
Key Concerns
- Insufficient output escaping detected
Advanced Custom Fields – Widget Relationship Field add-on Security Vulnerabilities
Advanced Custom Fields – Widget Relationship Field add-on Release Timeline
Advanced Custom Fields – Widget Relationship Field add-on Code Analysis
Output Escaping
Advanced Custom Fields – Widget Relationship Field add-on Attack Surface
AJAX Handlers 2
WordPress Hooks 1
Maintenance & Trust
Advanced Custom Fields – Widget Relationship Field add-on Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Custom Fields – Widget Relationship Field add-on Alternatives
Buckets
buckets
A widgets alternative that lets you place content anywhere easily.
Advanced Custom Fields: Widget Area Field
advanced-custom-fields-widget-area-field
Add-on to Advanced Custom Fields giving you a field to display Widget Areas.
Advanced Custom Fields: Widget
advanced-custom-fields-widget
A widget that is able to use content from an ACF field group
ACF Advanced Search
acf-advanced-search
Advanced search for the Advanced Custom Fields plugin (Free & Pro).
Widget Master
wp-widget-master
The Widget Master plugin lets visitors to choose what widgets/blocks he want or wont to see on your pages. Visitor can hide widgets per PHP session.
Advanced Custom Fields – Widget Relationship Field add-on Developer Profile
1 plugin · 600 total installs
How We Detect Advanced Custom Fields – Widget Relationship Field add-on
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-custom-fields-widget-relationship-field-add-on/widget-relationship-field-v4.phpHTML / DOM Fingerprints
acf_relationshiprelationship_leftrelationship_rightblrelationship_listload-moreacf-loadingrelationship-item-info+2 moredata-sidebardata-inherit_fromdata-menu_locationdata-pageddata-post_typedata-field_key+1 moreacf_Widget/wp-ajax/acf_Widget/get_widget_list