Advanced Custom Fields: WPML Language Selector Field Security & Risk Analysis

wordpress.org/plugins/advanced-custom-fields-wpml-language-selector

Custom field addon for Advanced Custom Fields plugin which provides a list of used WPML languages on website.

100 active installs v1.2.1 PHP + WP 4.0+ Updated Jan 25, 2016
acfcustom-fieldlanguagelanguage-selectwpml
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Advanced Custom Fields: WPML Language Selector Field Safe to Use in 2026?

Generally Safe

Score 85/100

Advanced Custom Fields: WPML Language Selector Field has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The static analysis of the 'advanced-custom-fields-wpml-language-selector' plugin v1.2.1 indicates a strong security posture with no identified entry points, dangerous functions, file operations, or external HTTP requests. The code strictly adheres to prepared statements for SQL queries and demonstrates a high level of output escaping, with only a small percentage of outputs potentially unescaped. The absence of any recorded vulnerabilities, CVEs, or critical taint flows further reinforces this positive security assessment. However, the complete lack of nonce checks and capability checks across all entry points, even though the attack surface is currently zero, represents a potential concern. If the plugin were to introduce new entry points in the future without implementing these crucial security measures, it could become vulnerable to various attacks. The plugin's history of zero vulnerabilities is a testament to its development practices, but a proactive approach to implementing authentication and authorization checks on all code paths, even those currently inactive, would further strengthen its overall security.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
  • Some outputs not properly escaped
Vulnerabilities
None known

Advanced Custom Fields: WPML Language Selector Field Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Advanced Custom Fields: WPML Language Selector Field Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
40 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

83% escaped48 total outputs
Attack Surface

Advanced Custom Fields: WPML Language Selector Field Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionacf/include_field_typesacf-wpml-language-selector.php:38
actionacf/register_fieldsacf-wpml-language-selector.php:39
Maintenance & Trust

Advanced Custom Fields: WPML Language Selector Field Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedJan 25, 2016
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Advanced Custom Fields: WPML Language Selector Field Developer Profile

Ivan Paulin

2 plugins · 3K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Advanced Custom Fields: WPML Language Selector Field

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Advanced Custom Fields: WPML Language Selector Field