
All custom fields & groups Security & Risk Analysis
wordpress.org/plugins/all-custom-fields-groups[ ✅ 𝐒𝐄𝐂𝐔𝐑𝐄 𝐏𝐋𝐔𝐆𝐈𝐍𝐒 b𝓎 𝒫𝓊𝓋𝑜𝓍 ] Output all custom fields from groups
Is All custom fields & groups Safe to Use in 2026?
Generally Safe
Score 92/100All custom fields & groups has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'all-custom-fields-groups' plugin version 1.08 exhibits a mixed security posture. While it demonstrates good practices by having a zero attack surface from common entry points like AJAX handlers, REST API routes, shortcodes, and cron events, and a significant percentage of its SQL queries utilize prepared statements, several concerns warrant attention. The presence of the `unserialize` function is a significant red flag, as it can lead to deserialization vulnerabilities if not handled with extreme care. The taint analysis further amplifies this concern, revealing a high number of flows with unsanitized paths, including one of high severity, indicating potential for input manipulation to exploit vulnerabilities. Furthermore, the output escaping is only moderately effective, with over half of the outputs not being properly escaped, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities. The plugin's vulnerability history, though currently showing no unpatched CVEs, includes a past medium-severity XSS vulnerability, reinforcing the importance of secure output handling and input validation. The plugin's strengths lie in its limited attack surface and proactive use of prepared statements. However, the risks associated with `unserialize`, unsanitized taint flows, and insufficient output escaping necessitate caution.
Key Concerns
- Presence of unserialize function
- High number of unsanitized taint flows
- High severity taint flow found
- Less than 100% output escaping
- Past medium CVE (XSS)
All custom fields & groups Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
All custom fields & groups <= 1.04 - Reflected Cross-Site Scripting
All custom fields & groups Release Timeline
All custom fields & groups Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
All custom fields & groups Attack Surface
WordPress Hooks 35
Maintenance & Trust
All custom fields & groups Maintenance & Trust
Maintenance Signals
Community Trust
All custom fields & groups Alternatives
Shortcode Enablr
shortcode-enablr
Enable shortcodes in ACF field and Yoast SEO titles.
Better Field Groups for ACF
better-field-groups-for-acf
Remove distracting edit icons from ACF (and SCF) field groups, creating a cleaner, more professional interface for content editors.
Advanced Custom Fields (ACF®)
advanced-custom-fields
ACF helps customize WordPress with powerful, professional and intuitive fields. Proudly powering over 2 million sites, WordPress developers love ACF.
ACF Content Analysis for Yoast SEO
acf-content-analysis-for-yoast-seo
WordPress plugin that adds the content of all ACF fields to the Yoast SEO score analysis.
Advanced Custom Fields: Extended
acf-extended
All-in-one enhancement suite that improves WordPress & Advanced Custom Fields.
All custom fields & groups Developer Profile
19 plugins · 51K total installs
How We Detect All custom fields & groups
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/all-custom-fields-groups/assets/style.cssHTML / DOM Fingerprints
acf_fieldsgrouplabelvaluedata-acf_groupacf[custom_fields_groups]