
All custom fields & groups Security & Risk Analysis
wordpress.org/plugins/all-custom-fields-groups[ โ ๐๐๐๐๐๐ ๐๐๐๐๐๐๐ b๐ ๐ซ๐๐๐๐ ] Output all custom fields from groups
Is All custom fields & groups Safe to Use in 2026?
Generally Safe
Score 92/100All custom fields & groups has a strong security track record. Known vulnerabilities have been patched promptly.
The 'all-custom-fields-groups' plugin version 1.08 exhibits a mixed security posture. While it demonstrates good practices by having a zero attack surface from common entry points like AJAX handlers, REST API routes, shortcodes, and cron events, and a significant percentage of its SQL queries utilize prepared statements, several concerns warrant attention. The presence of the `unserialize` function is a significant red flag, as it can lead to deserialization vulnerabilities if not handled with extreme care. The taint analysis further amplifies this concern, revealing a high number of flows with unsanitized paths, including one of high severity, indicating potential for input manipulation to exploit vulnerabilities. Furthermore, the output escaping is only moderately effective, with over half of the outputs not being properly escaped, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities. The plugin's vulnerability history, though currently showing no unpatched CVEs, includes a past medium-severity XSS vulnerability, reinforcing the importance of secure output handling and input validation. The plugin's strengths lie in its limited attack surface and proactive use of prepared statements. However, the risks associated with `unserialize`, unsanitized taint flows, and insufficient output escaping necessitate caution.
Key Concerns
- Presence of unserialize function
- High number of unsanitized taint flows
- High severity taint flow found
- Less than 100% output escaping
- Past medium CVE (XSS)
All custom fields & groups Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
All custom fields & groups <= 1.04 - Reflected Cross-Site Scripting
All custom fields & groups Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
All custom fields & groups Attack Surface
WordPress Hooks 35
Maintenance & Trust
All custom fields & groups Maintenance & Trust
Maintenance Signals
Community Trust
All custom fields & groups Alternatives
Shortcode Enablr
shortcode-enablr
Enable shortcodes in ACF field and Yoast SEO titles.
Advanced Custom Fields (ACFยฎ)
advanced-custom-fields
ACF helps customize WordPress with powerful, professional and intuitive fields. Proudly powering over 2 million sites, WordPress developers love ACF.
ACF Content Analysis for Yoast SEO
acf-content-analysis-for-yoast-seo
WordPress plugin that adds the content of all ACF fields to the Yoast SEO score analysis.
Advanced Custom Fields: Extended
acf-extended
All-in-one enhancement suite that improves WordPress & Advanced Custom Fields.
Advanced Custom Fields: Font Awesome Field
advanced-custom-fields-font-awesome
Adds a new 'Font Awesome Icon' field to the popular Advanced Custom Fields plugin.
All custom fields & groups Developer Profile
16 plugins ยท 51K total installs
How We Detect All custom fields & groups
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/all-custom-fields-groups/assets/style.cssHTML / DOM Fingerprints
acf_fieldsgrouplabelvaluedata-acf_groupacf[custom_fields_groups]