LuckyWP ACF Menu Field Security & Risk Analysis

wordpress.org/plugins/luckywp-acf-menu-field

Add navigation menu field type to Advanced Custom Fields

5K active installs v1.0.3 PHP 5.6.20+ WP 4.7+ Updated Jun 10, 2025
acfadvanced-custom-fieldsmenumenusnav-menu
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is LuckyWP ACF Menu Field Safe to Use in 2026?

Generally Safe

Score 100/100

LuckyWP ACF Menu Field has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The luckywp-acf-menu-field plugin v1.0.3 exhibits a strong security posture in several key areas. The static analysis reveals no identified AJAX handlers, REST API routes, shortcodes, or cron events, significantly limiting the potential attack surface. Furthermore, the plugin demonstrates good practices by not utilizing dangerous functions, performing file operations, or making external HTTP requests. All SQL queries are correctly using prepared statements, and there is a history of zero known vulnerabilities, indicating a well-maintained and secure codebase. The absence of taint analysis findings further reinforces this positive outlook.

However, a significant concern arises from the output escaping results. With 17 total outputs and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is displayed without proper sanitization or escaping is susceptible to malicious injection. While the plugin has a capability check, the lack of nonce checks on potential entry points (if any were present and not flagged by the limited static analysis) could also be a theoretical concern, though no specific entry points were identified.

In conclusion, the plugin benefits from a minimal attack surface and absence of known vulnerabilities and potentially risky code patterns. The primary weakness lies in the complete lack of output escaping, which presents a critical risk that needs immediate attention. Addressing the output escaping issue should be the highest priority to mitigate potential XSS attacks.

Key Concerns

  • 0% output escaping
Vulnerabilities
None known

LuckyWP ACF Menu Field Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

LuckyWP ACF Menu Field Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped17 total outputs
Attack Surface

LuckyWP ACF Menu Field Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_menuadmin\Plugins.php:19
filterinstall_plugins_nonmenu_tabsadmin\Plugins.php:37
filterinstall_plugins_table_api_args_luckywpadmin\Plugins.php:41
actionafter_setup_themecore\base\BasePlugin.php:66
actioninitcore\pluginRate\PluginRate.php:19
actionadmin_noticescore\pluginRate\PluginRate.php:21
actionadmin_enqueue_scriptscore\pluginRate\PluginRate.php:25
actionacf/include_field_typesplugin\Plugin.php:20
Maintenance & Trust

LuckyWP ACF Menu Field Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 10, 2025
PHP min version5.6.20
Downloads54K

Community Trust

Rating100/100
Number of ratings19
Active installs5K
Developer Profile

LuckyWP ACF Menu Field Developer Profile

LuckyWP

5 plugins · 119K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
174 days
View full developer profile
Detection Fingerprints

How We Detect LuckyWP ACF Menu Field

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/luckywp-acf-menu-field/core/pluginRate/main.min.css/wp-content/plugins/luckywp-acf-menu-field/core/pluginRate/main.min.js
Script Paths
/wp-content/plugins/luckywp-acf-menu-field/core/pluginRate/main.min.js
Version Parameters
luckywp-acf-menu-field/core/pluginRate/main.min.css?ver=luckywp-acf-menu-field/core/pluginRate/main.min.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-prefixdata-trim-prefix
JS Globals
lwpamfPluginRate
REST Endpoints
/wp-json/luckywp-acf-menu-field/v1
FAQ

Frequently Asked Questions about LuckyWP ACF Menu Field