Dynamic Fields for Elementor and SCF/ACF Security & Risk Analysis

wordpress.org/plugins/dynamic-fields-for-elementor-scf-acf

Dynamically manage custom SCF/ACF fields into Elementor Page Settings with various field types.

40 active installs v1.0.9 PHP 7.4+ WP 6.0+ Updated Feb 12, 2026
acfcustom-fieldsdynamicelementorfields
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Dynamic Fields for Elementor and SCF/ACF Safe to Use in 2026?

Generally Safe

Score 100/100

Dynamic Fields for Elementor and SCF/ACF has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "dynamic-fields-for-elementor-scf-acf" plugin version 1.0.9 exhibits a strong security posture. The absence of any identified CVEs, dangerous functions, raw SQL queries, file operations, or external HTTP requests is a significant positive indicator. Furthermore, the data shows a complete lack of taint flows and unsanitized paths, suggesting robust input validation and sanitization practices within the analyzed code. The plugin also demonstrates good output escaping with 92% of outputs properly handled and includes capability checks, which are crucial for access control.

While the plugin presents a minimal attack surface with no identified unprotected entry points (AJAX, REST API, shortcodes, cron), a notable concern is the complete absence of nonce checks. This lack of nonce validation on potential entry points, even if currently zero, represents a potential vulnerability that could be exploited if new AJAX handlers or other interactive features are added without proper security considerations. This is the primary area for improvement, as it leaves a gap that could be exploited in future development or if an attack vector is discovered that leverages these entry points.

In conclusion, the plugin is generally well-secured, with excellent handling of SQL queries and output, and a clean vulnerability history. However, the absence of nonce checks across all entry points, however small the current attack surface may be, introduces a latent risk. Addressing this by implementing nonce checks on any interactive or state-changing functionality would significantly enhance its overall security.

Key Concerns

  • No nonce checks found on entry points
Vulnerabilities
None known

Dynamic Fields for Elementor and SCF/ACF Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Dynamic Fields for Elementor and SCF/ACF Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
23 escaped
Nonce Checks
0
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

92% escaped25 total outputs
Attack Surface

Dynamic Fields for Elementor and SCF/ACF Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_noticesdynamic-fields-for-elementor-scf-acf.php:28
actionadmin_menudynamic-fields-for-elementor-scf-acf.php:51
actionadmin_initdynamic-fields-for-elementor-scf-acf.php:60
actionadmin_enqueue_scriptsdynamic-fields-for-elementor-scf-acf.php:123
actionelementor/documents/register_controlsdynamic-fields-for-elementor-scf-acf.php:349
actionelementor/document/after_savedynamic-fields-for-elementor-scf-acf.php:386
actionacf/save_postdynamic-fields-for-elementor-scf-acf.php:427
Maintenance & Trust

Dynamic Fields for Elementor and SCF/ACF Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 12, 2026
PHP min version7.4
Downloads66K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Dynamic Fields for Elementor and SCF/ACF Developer Profile

Ankit Patel

3 plugins · 40 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Dynamic Fields for Elementor and SCF/ACF

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dynamic-fields-for-elementor-scf-acf/assest/dffescfacf-admin-style.css/wp-content/plugins/dynamic-fields-for-elementor-scf-acf/assest/dffescfacf-admin-script.js
Script Paths
/wp-content/plugins/dynamic-fields-for-elementor-scf-acf/assest/dffescfacf-admin-script.js
Version Parameters
dynamic-fields-for-elementor-scf-acf/assest/dffescfacf-admin-style.css?ver=dynamic-fields-for-elementor-scf-acf/assest/dffescfacf-admin-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
dffe-scf-scf-wrapper
FAQ

Frequently Asked Questions about Dynamic Fields for Elementor and SCF/ACF