Fields ACF & SCF for Elementor and Divi Security & Risk Analysis

wordpress.org/plugins/lknscf-extended

Fields ACF & SCF for Elementor and Divi.

30 active installs v2.1.3 PHP 7.2+ WP 5.7+ Updated Nov 26, 2025
acfdivielementorgalleryscf
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Fields ACF & SCF for Elementor and Divi Safe to Use in 2026?

Generally Safe

Score 100/100

Fields ACF & SCF for Elementor and Divi has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The plugin 'lknscf-extended' v2.1.3 exhibits a generally strong security posture based on the provided static analysis. The code demonstrates excellent practices by using prepared statements for all SQL queries and properly escaping all output. The absence of file operations and external HTTP requests further reduces potential attack vectors. A significant strength is the complete lack of recorded vulnerabilities and CVEs, indicating a history of secure development and maintenance.

However, there is a notable concern regarding the attack surface. The analysis identifies one AJAX handler that lacks authentication checks. This unprotected entry point presents a direct risk, as it could potentially be exploited by unauthenticated users to trigger unintended actions or access sensitive functionality. While the taint analysis shows no detected flows, this doesn't entirely negate the risk of the unprotected AJAX handler, as taint analysis may not cover all scenarios or types of vulnerabilities. The plugin also doesn't appear to implement capability checks, which, in conjunction with the unprotected AJAX handler, could allow broader unauthorized access.

In conclusion, 'lknscf-extended' v2.1.3 is strong in its handling of data and general code security. The historical absence of vulnerabilities is a positive indicator. The primary weakness lies in the unprotected AJAX endpoint, which requires immediate attention to mitigate potential security risks. Implementing proper authentication and authorization for this handler is crucial to fortify the plugin's security.

Key Concerns

  • Unprotected AJAX handler
  • Missing capability checks
Vulnerabilities
None known

Fields ACF & SCF for Elementor and Divi Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Fields ACF & SCF for Elementor and Divi Release Timeline

v2.1.3Current
v2.1.2
v2.1.1
v2.1.0
v2.0.0
Code Analysis
Analyzed Apr 16, 2026

Fields ACF & SCF for Elementor and Divi Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
299 escaped
Nonce Checks
12
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped299 total outputs
Attack Surface
1 unprotected

Fields ACF & SCF for Elementor and Divi Attack Surface

Entry Points3
Unprotected1

AJAX Handlers 1

authwp_ajax_lknscf_loopIncludes/LknscfExtended.php:256

Shortcodes 2

[lknscf_gallery] Includes/LknscfExtended.php:277
[lknscf_field] Includes/LknscfExtended.php:278
WordPress Hooks 14
actionadmin_enqueue_scriptsIncludes/LknscfExtended.php:133
actionadmin_enqueue_scriptsIncludes/LknscfExtended.php:134
actioninitIncludes/LknscfExtended.php:137
filterplugin_action_linksIncludes/LknscfExtended.php:138
actionelementor/initIncludes/LknscfExtended.php:143
actionelementor/dynamic_tags/registerIncludes/LknscfExtended.php:144
actionet_builder_readyIncludes/LknscfExtended.php:148
actionadmin_menuIncludes/LknscfExtended.php:151
actionadmin_initIncludes/LknscfExtended.php:152
actionwp_enqueue_scriptsIncludes/LknscfExtended.php:248
actionwp_enqueue_scriptsIncludes/LknscfExtended.php:249
actioninitIncludes/LknscfExtended.php:252
filterget_media_item_argsIncludes/fields/LknscfExtendedGalleryField.php:35
actionadmin_noticeslknscf-extended.php:112
Maintenance & Trust

Fields ACF & SCF for Elementor and Divi Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 26, 2025
PHP min version7.2
Downloads940

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Fields ACF & SCF for Elementor and Divi Developer Profile

linknacional

20 plugins · 7K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
13 days
View full developer profile
Detection Fingerprints

How We Detect Fields ACF & SCF for Elementor and Divi

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lknscf-extended/Admin/css/lknscfExtendedAdmin.css/wp-content/plugins/lknscf-extended/Admin/js/lkn-gallery-script.js
Script Paths
/wp-content/plugins/lknscf-extended/Admin/js/lkn-gallery-script.js
Version Parameters
lknscf-extended/Admin/css/lknscfExtendedAdmin.css?ver=lknscf-extended/Admin/js/lkn-gallery-script.js?ver=

HTML / DOM Fingerprints

JS Globals
window.lknscfGlobal
FAQ

Frequently Asked Questions about Fields ACF & SCF for Elementor and Divi