Flexible Layout Preview Image for ACF Security & Risk Analysis

wordpress.org/plugins/flexible-layout-preview-image-for-acf

Adds flexible layout preview images for Advanced Custom Fields (ACF) in the WordPress admin.

500 active installs v1.4.2 PHP 7.4+ WP 5.0+ Updated Sep 2, 2025
acfadminadvanced-custom-fieldsflexible-contentlayout-preview
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Flexible Layout Preview Image for ACF Safe to Use in 2026?

Generally Safe

Score 100/100

Flexible Layout Preview Image for ACF has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The plugin "flexible-layout-preview-image-for-acf" v1.4.2 exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code signals indicate a lack of dangerous functions, secure handling of SQL queries through prepared statements, and no file operations or external HTTP requests. This suggests a carefully developed plugin with a focus on secure coding practices.

While the static analysis reveals no critical or high-severity issues, there are minor areas for improvement. The fact that only 67% of output is properly escaped, with 3 total outputs, implies a potential for cross-site scripting (XSS) vulnerabilities if the unescaped outputs are rendered in a context where they can be manipulated by attackers. The complete absence of nonce and capability checks, although perhaps mitigated by the lack of entry points, is a general security weakness that could become problematic if the plugin were to be expanded in the future.

The plugin's vulnerability history is exceptionally clean, with zero known CVEs and no recorded past vulnerabilities. This is a very positive indicator of ongoing security maintenance and a low likelihood of existing exploitable flaws. In conclusion, the plugin is currently very secure due to its minimal attack surface and good coding practices, with the primary concern being the small percentage of unescaped output. The lack of historical vulnerabilities is a significant strength.

Key Concerns

  • Unescaped output detected
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Flexible Layout Preview Image for ACF Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Flexible Layout Preview Image for ACF Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped3 total outputs
Attack Surface

Flexible Layout Preview Image for ACF Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_footerflexible-layout-preview-image-for-acf.php:31
actionadmin_footerflexible-layout-preview-image-for-acf.php:32
actionacf/input/admin_footerflexible-layout-preview-image-for-acf.php:35
actionacf/input/admin_headflexible-layout-preview-image-for-acf.php:38
actioninitflexible-layout-preview-image-for-acf.php:40
filterplugin_row_metaflexible-layout-preview-image-for-acf.php:204
Maintenance & Trust

Flexible Layout Preview Image for ACF Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 2, 2025
PHP min version7.4
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs500
Developer Profile

Flexible Layout Preview Image for ACF Developer Profile

Galaxy Weblinks

40 plugins · 25K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
310 days
View full developer profile
Detection Fingerprints

How We Detect Flexible Layout Preview Image for ACF

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/flexible-layout-preview-image-for-acf/assets/js/flexible-layout-preview-image-for-acf.js/wp-content/plugins/flexible-layout-preview-image-for-acf/assets/css/flexible-layout-preview-image-for-acf.css
Script Paths
assets/js/flexible-layout-preview-image-for-acf.js
Version Parameters
flexible-layout-preview-image-for-acf/assets/js/flexible-layout-preview-image-for-acf.js?ver=flexible-layout-preview-image-for-acf/assets/css/flexible-layout-layout-preview-image-for-acf.css?ver=

HTML / DOM Fingerprints

CSS Classes
acf-fc-popupacf-fc-popup-image
HTML Comments
Flexible Content Preview for Advanced Custom Fields: dynamic images
Data Attributes
data-layout
FAQ

Frequently Asked Questions about Flexible Layout Preview Image for ACF