Field block for ACF PRO Security & Risk Analysis

wordpress.org/plugins/field-block-for-acf-pro

No code solution to display ACF fields using the ACF field block.

20 active installs v1.3.1 PHP + WP 6.2+ Updated Mar 18, 2024
acfblockfield
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Field block for ACF PRO Safe to Use in 2026?

Generally Safe

Score 85/100

Field block for ACF PRO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The 'field-block-for-acf-pro' v1.3.1 plugin exhibits a strong security posture based on the provided static analysis. The plugin has no identified entry points like AJAX handlers, REST API routes, or shortcodes, which significantly reduces its attack surface. Furthermore, it demonstrates good coding practices by utilizing prepared statements for all SQL queries and effectively escaping the vast majority of its output. The absence of dangerous functions, file operations, external HTTP requests, and bundled libraries further contributes to a secure foundation. The taint analysis showing no flows with unsanitized paths, critical or high severity, reinforces this positive assessment.

While the static analysis reveals a clean codebase with no immediate vulnerabilities, the complete absence of nonces and capability checks across its entire (albeit zero) attack surface is a notable observation. This could indicate either a truly minimal plugin or a potential oversight if the plugin's functionality, when expanded, relies on user input or actions that would typically require such protections. The vulnerability history being entirely clear is a very positive sign, suggesting a well-maintained and robust plugin. However, it's important to note that past security performance doesn't guarantee future security. Overall, the plugin appears to be securely coded with minimal risk, but vigilance regarding the absence of specific security checks for potential future expansion is warranted.

Key Concerns

  • No Nonce Checks Identified
  • No Capability Checks Identified
Vulnerabilities
None known

Field block for ACF PRO Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Field block for ACF PRO Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
63 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

93% escaped68 total outputs
Attack Surface

Field block for ACF PRO Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filteracf/prepare_field/name=acf-field-namefield-block-for-acf-pro.php:68
actionacf/include_fieldsfield-block-for-acf-pro.php:89
actionacf/initfield-block-for-acf-pro.php:90
filteracf/fields/google_map/apifield-block-for-acf-pro.php:91
Maintenance & Trust

Field block for ACF PRO Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMar 18, 2024
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Field block for ACF PRO Developer Profile

bobbingwide

16 plugins · 7K total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
15 days
View full developer profile
Detection Fingerprints

How We Detect Field block for ACF PRO

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/field-block-for-acf-pro/assets/dist/style-index.css/wp-content/plugins/field-block-for-acf-pro/assets/dist/editor.css/wp-content/plugins/field-block-for-acf-pro/assets/dist/view.js
Script Paths
/wp-content/plugins/field-block-for-acf-pro/assets/dist/editor.js
Version Parameters
field-block-for-acf-pro/assets/dist/style-index.css?ver=field-block-for-acf-pro/assets/dist/editor.css?ver=field-block-for-acf-pro/assets/dist/view.js?ver=field-block-for-acf-pro/assets/dist/editor.js?ver=

HTML / DOM Fingerprints

CSS Classes
acf-field-acf-type-has-label
HTML Comments
<!-- field-block-for-acf-pro --><!-- END field-block-for-acf-pro -->
Data Attributes
data-acf-field-namedata-display-label
JS Globals
wp.blocks.registerBlockTypewp.element.createElementwindow.acf_field_block_renderer
FAQ

Frequently Asked Questions about Field block for ACF PRO