
Ajax Load More for Advanced Custom Fields Security & Risk Analysis
wordpress.org/plugins/ajax-load-more-for-acfAjax Load More extension that adds compatibility with various field types for Advanced Custom Fields.
Is Ajax Load More for Advanced Custom Fields Safe to Use in 2026?
Generally Safe
Score 100/100Ajax Load More for Advanced Custom Fields has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ajax-load-more-for-acf" plugin v1.4.0 exhibits a concerning security posture due to a significant lack of proper authentication and authorization checks on its entry points. While the plugin demonstrates good practices in areas like SQL query preparation and output escaping, the presence of two AJAX handlers without any form of nonce or capability checks presents a substantial risk. This means any unauthenticated user could potentially trigger these AJAX actions, which could lead to unintended consequences or even exploit vulnerabilities if the functionality they trigger is insecure.
The static analysis shows a clean slate regarding dangerous functions, SQL injection vulnerabilities, unescaped output, file operations, and external HTTP requests. The absence of any recorded vulnerabilities in its history is a positive sign, suggesting a generally well-maintained codebase over time. However, the vulnerability history doesn't negate the immediate risks identified in the static analysis. The current version has a notable weakness in its attack surface design, specifically around its AJAX endpoints.
In conclusion, the plugin has strengths in its secure handling of data and output. However, the critical oversight of not implementing authentication checks on its AJAX handlers creates a significant and immediate security risk. This weakness overshadows the positive aspects and requires immediate attention to secure the plugin's entry points.
Key Concerns
- AJAX handlers without authorization checks
- No nonce checks on AJAX handlers
- No capability checks on AJAX handlers
Ajax Load More for Advanced Custom Fields Security Vulnerabilities
Ajax Load More for Advanced Custom Fields Code Analysis
Ajax Load More for Advanced Custom Fields Attack Surface
AJAX Handlers 2
WordPress Hooks 4
Maintenance & Trust
Ajax Load More for Advanced Custom Fields Maintenance & Trust
Maintenance Signals
Community Trust
Ajax Load More for Advanced Custom Fields Alternatives
ACF Content Analysis for Yoast SEO
acf-content-analysis-for-yoast-seo
WordPress plugin that adds the content of all ACF fields to the Yoast SEO score analysis.
Advanced Custom Fields: Font Awesome Field
advanced-custom-fields-font-awesome
Adds a new 'Font Awesome Icon' field to the popular Advanced Custom Fields plugin.
Table Field Add-on for ACF and SCF
advanced-custom-fields-table-field
A Table Field Add-on for the Advanced Custom Fields and Secure Custom Fields Plugin.
ACF: Better Search
acf-better-search
This plugin adds to default WordPress search engine the ability to search by content from selected fields of Advanced Custom Fields plugin.
WP All Import – Import Add-On for ACF
csv-xml-import-for-acf
Drag & drop to import any CSV, Excel, XML, or Google Sheets file into Advanced Custom Fields. Supports repeaters, flexible content, galleries, and …
Ajax Load More for Advanced Custom Fields Developer Profile
9 plugins · 47K total installs
How We Detect Ajax Load More for Advanced Custom Fields
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ajax-load-more-for-acf/css/alm-acf.css/wp-content/plugins/ajax-load-more-for-acf/js/alm-acf.js/wp-content/plugins/ajax-load-more-for-acf/js/alm-acf.jsajax-load-more-for-acf/css/alm-acf.css?ver=ajax-load-more-for-acf/js/alm-acf.js?ver=HTML / DOM Fingerprints
data-alm-acf-field-typedata-alm-acf-field-namedata-alm-acf-parent-field-namedata-alm-acf-row-indexalm_acf_vars