
GeoMeta For ACF Security & Risk Analysis
wordpress.org/plugins/geometa-acfStore real spatial data with Advanced Custom Fields, using the WP-GeoMeta library.
Is GeoMeta For ACF Safe to Use in 2026?
Generally Safe
Score 85/100GeoMeta For ACF has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The geometa-acf plugin version 0.0.4 exhibits a strong overall security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength, limiting the attack surface to zero. Furthermore, the code's adherence to prepared statements for all SQL queries is excellent, mitigating the risk of SQL injection vulnerabilities. The lack of identified critical or high severity taint flows and a clean vulnerability history with zero known CVEs are also highly positive indicators.
However, there are areas for concern. The output escaping is only properly implemented in 64% of cases, leaving a significant portion of outputs potentially vulnerable to Cross-Site Scripting (XSS) attacks. The complete absence of nonce checks and capability checks across all code signals a lack of fundamental security measures that are crucial for protecting against common WordPress attacks, especially if the attack surface were to grow in future versions or if new entry points were introduced. The presence of file operations, while not explicitly flagged as problematic, warrants attention as they can sometimes be exploited if not handled with extreme care and proper sanitization.
In conclusion, geometa-acf v0.0.4 demonstrates a commendable effort in preventing common web vulnerabilities like SQL injection and limiting its direct attack surface. Its clean vulnerability history suggests responsible development. Nevertheless, the significant number of unescaped outputs and the complete absence of nonce and capability checks represent critical security gaps that could be exploited, particularly if the plugin's functionality evolves. Addressing these specific weaknesses should be a priority to achieve a more robust security profile.
Key Concerns
- Insufficient output escaping
- Missing nonce checks
- Missing capability checks
GeoMeta For ACF Security Vulnerabilities
GeoMeta For ACF Code Analysis
SQL Query Safety
Output Escaping
GeoMeta For ACF Attack Surface
WordPress Hooks 9
Maintenance & Trust
GeoMeta For ACF Maintenance & Trust
Maintenance Signals
Community Trust
GeoMeta For ACF Alternatives
Advanced Members for ACF
advanced-members
A Lightweight & Powerful Membership Plugin for ACF Users. Seamlessly Use ACF Field Groups as Membership Forms
Brilliant Geocoder for Gravity Forms
brilliant-geocoder-gravity-forms
Capture location information in Gravity Forms by geocoding user's input into other form fields.
WP Spatial Capabilities Check
wp-spatial-capabilities-check
Creates a page in the dashboard with a list of the spatial functions your database supports so you can do GIS with MySQL or MariaDB in WordPress.
ACF Content Analysis for Yoast SEO
acf-content-analysis-for-yoast-seo
WordPress plugin that adds the content of all ACF fields to the Yoast SEO score analysis.
Advanced Custom Fields: Font Awesome Field
advanced-custom-fields-font-awesome
Adds a new 'Font Awesome Icon' field to the popular Advanced Custom Fields plugin.
GeoMeta For ACF Developer Profile
4 plugins · 150 total installs
How We Detect GeoMeta For ACF
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/geometa-acf/css/geometa-acf.css/wp-content/plugins/geometa-acf/js/geometa-acf.js/wp-content/plugins/geometa-acf/js/geometa-acf.jsgeometa-acf/css/geometa-acf.css?ver=geometa-acf/js/geometa-acf.js?ver=HTML / DOM Fingerprints
acf-field-geometaname="geometa"data-input_type="map"data-input_type="latlng"data-input_type="geojson"acf_geometa_params