
Calculated fields for ACF Security & Risk Analysis
wordpress.org/plugins/calculated-fields-for-acfSimple field math for Advanced Custom Fields.
Is Calculated fields for ACF Safe to Use in 2026?
Generally Safe
Score 85/100Calculated fields for ACF has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "calculated-fields-for-acf" plugin v1.3.2 exhibits a mixed security posture. On the positive side, the plugin demonstrates excellent SQL query handling by exclusively using prepared statements and shows a good rate of output escaping, with only one output unescaped. It also has no recorded vulnerability history and no flagged dangerous functions, file operations, or external HTTP requests. This suggests a level of care in development regarding common web application vulnerabilities.
However, significant concerns arise from the attack surface analysis. The plugin exposes two AJAX handlers, both of which lack any authentication or capability checks. This creates a substantial risk, as any unauthenticated user could potentially interact with these handlers, leading to unexpected behavior or the exploitation of underlying vulnerabilities if they exist within these handlers. The absence of nonce checks on these AJAX endpoints further exacerbates this risk, making them susceptible to Cross-Site Request Forgery (CSRF) attacks.
The overall security posture is therefore weakened by the presence of unprotected entry points, despite good practices in other areas like SQL and output sanitization. While the lack of historical vulnerabilities is encouraging, the current static analysis reveals a critical security gap that needs immediate attention to mitigate potential risks.
Key Concerns
- Unprotected AJAX handlers
- Missing nonce checks on AJAX
- Unescaped output
Calculated fields for ACF Security Vulnerabilities
Calculated fields for ACF Code Analysis
Output Escaping
Calculated fields for ACF Attack Surface
AJAX Handlers 2
WordPress Hooks 7
Maintenance & Trust
Calculated fields for ACF Maintenance & Trust
Maintenance Signals
Community Trust
Calculated fields for ACF Alternatives
Advanced Custom Fields: Extended
acf-extended
All-in-one enhancement suite that improves WordPress & Advanced Custom Fields.
ACF qTranslate
acf-qtranslate
Provides qTranslate compatible ACF field types for Text, Text Area, WYSIWYG, Image and File.
Admin Columns for ACF Fields
admin-columns-for-acf-fields
Allows you to enable columns for your ACF fields in post and taxonomy overviews (e.g. "All Posts") in the Wordpress admin backend.
Advanced Custom Fields: Typography Field
acf-typography-field
A Typography Add-on for the Advanced Custom Fields Plugin.
ACF: Google Map Extended
advanced-custom-fields-google-map-extended
ACF field. Saves map center, zoom level. Disables map zooming on scroll. Shows location coordinates. Bonus for programmers.
Calculated fields for ACF Developer Profile
2 plugins · 1K total installs
How We Detect Calculated fields for ACF
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/calculated-fields-for-acf/admin/assets/calculated-fields-for-acf.js/wp-content/plugins/calculated-fields-for-acf/admin/assets/calculated-fields-for-acf.min.js/wp-content/plugins/calculated-fields-for-acf/admin/assets/calculated-fields-for-acf.js/wp-content/plugins/calculated-fields-for-acf/admin/assets/calculated-fields-for-acf.min.jscalculated-fields-for-acf/style.css?ver=calculated-fields-for-acf/admin/assets/calculated-fields-for-acf.js?ver=HTML / DOM Fingerprints
data-formuladata-calculated_formatdata-blank_if_zerodata-readonlyCalculatedFields