
Metaly for ACF and SCF Security & Risk Analysis
wordpress.org/plugins/metaly-for-acf-and-scfSupercharge ACF/SCF with modern, production-ready field types designed for real-world content workflows.
Is Metaly for ACF and SCF Safe to Use in 2026?
Generally Safe
Score 100/100Metaly for ACF and SCF has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "metaly-for-acf-and-scf" plugin v1.0.0 exhibits a concerning security posture primarily due to its unprotected AJAX handlers. While the plugin demonstrates good practices in other areas, such as 100% proper output escaping and the use of prepared statements for SQL queries, the presence of three AJAX handlers without any authentication checks represents a significant entry point for potential attacks. This lack of authorization could allow unauthenticated users to trigger arbitrary actions within the plugin, leading to various security issues depending on the functionality exposed. The absence of known CVEs and successful taint analysis for critical or high vulnerabilities is a positive sign, suggesting that the core code might be relatively clean or that the specific functionality doesn't lend itself to common exploitation patterns. However, this does not negate the immediate risk posed by the unprotected AJAX endpoints. The plugin's vulnerability history being clean is reassuring, but it's important to remember that new vulnerabilities can emerge, especially with the identified attack surface.
Key Concerns
- 3 unprotected AJAX handlers
Metaly for ACF and SCF Security Vulnerabilities
Metaly for ACF and SCF Release Timeline
Metaly for ACF and SCF Code Analysis
Bundled Libraries
Output Escaping
Metaly for ACF and SCF Attack Surface
AJAX Handlers 3
WordPress Hooks 5
Maintenance & Trust
Metaly for ACF and SCF Maintenance & Trust
Maintenance Signals
Community Trust
Metaly for ACF and SCF Alternatives
Table Field Add-on for ACF and SCF
advanced-custom-fields-table-field
A Table Field Add-on for the Advanced Custom Fields and Secure Custom Fields Plugin.
Sekura REST Bridge for ACF
sekura-rest-bridge-for-acf
Expose Advanced Custom Fields in the WordPress REST API with proper access control.
Advanced Custom Fields (ACF®)
advanced-custom-fields
ACF helps customize WordPress with powerful, professional and intuitive fields. Proudly powering over 2 million sites, WordPress developers love ACF.
ACF Content Analysis for Yoast SEO
acf-content-analysis-for-yoast-seo
WordPress plugin that adds the content of all ACF fields to the Yoast SEO score analysis.
Advanced Custom Fields: Extended
acf-extended
All-in-one enhancement suite that improves WordPress & Advanced Custom Fields.
Metaly for ACF and SCF Developer Profile
8 plugins · 190 total installs
How We Detect Metaly for ACF and SCF
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/metaly-for-acf-and-scf/admin/css/metaly-admin.css/wp-content/plugins/metaly-for-acf-and-scf/admin/js/metaly-admin.jsadmin/js/metaly-admin.jsmetaly-admin.css?ver=metaly-admin.js?ver=HTML / DOM Fingerprints
<!-- Address Field --><!-- HTML Field --><!-- QR Code Field --><!-- Code Scan Field -->+13 moredata-address-fielddata-html-fielddata-qr-code-fielddata-code-scan-fielddata-likert-scale-fielddata-signature-field+11 moremetaly_fs