Quick and Easy Post creation for ACF Relationship Fields Security & Risk Analysis

wordpress.org/plugins/quick-and-easy-post-creation-for-acf-relationship-fields

Quick & Easy Post creation on your Advanced Custom Fields (ACF) 'Relationship' & 'Post Object' Fields

50 active installs v2.2 PHP + WP 4.5+ Updated Sep 15, 2016
acfadvanced-custom-fieldsfieldpost-objectrelationship
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Quick and Easy Post creation for ACF Relationship Fields Safe to Use in 2026?

Generally Safe

Score 85/100

Quick and Easy Post creation for ACF Relationship Fields has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The plugin 'quick-and-easy-post-creation-for-acf-relationship-fields' v2.2 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by not using dangerous functions, performing all SQL queries using prepared statements, and largely escaping output. It also has no known vulnerabilities or CVEs, suggesting a generally well-maintained codebase. However, a significant concern is the presence of one AJAX handler that lacks authentication checks. This creates a direct entry point into the plugin's functionality that is accessible to any user, regardless of their WordPress role or permissions. The absence of taint analysis findings is positive but does not negate the risks associated with an unprotected AJAX endpoint.

While the plugin has a clean vulnerability history, this does not guarantee future security. The single unprotected AJAX handler represents a notable weakness that could be exploited if the handler performs sensitive operations or exposes information. The lack of nonce checks and capability checks on this handler further exacerbates the risk. In conclusion, the plugin's strengths lie in its secure handling of database operations and output, but the unprotected AJAX endpoint is a critical flaw that demands immediate attention to prevent potential security breaches.

Key Concerns

  • Unprotected AJAX handler
  • Missing nonce checks on AJAX
  • Missing capability checks on AJAX
  • Minor unescaped output (1 out of 6)
Vulnerabilities
None known

Quick and Easy Post creation for ACF Relationship Fields Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Quick and Easy Post creation for ACF Relationship Fields Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

83% escaped6 total outputs
Attack Surface
1 unprotected

Quick and Easy Post creation for ACF Relationship Fields Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_acf_rc_incrementacf-relationship-create.php:69
WordPress Hooks 8
actionplugins_loadedacf-relationship-create.php:59
actioninitacf-relationship-create.php:62
actionadmin_noticesacf-relationship-create.php:137
actionadmin_enqueue_scriptsacf-relationship-create.php:183
actionacf/input/admin_enqueue_scriptsacf-relationship-create.php:196
filteracf/fields/relationship/queryacf-relationship-create.php:199
actionacf/create_field_optionsacf-relationship-create.php:202
actionacf/create_fieldacf-relationship-create.php:205
Maintenance & Trust

Quick and Easy Post creation for ACF Relationship Fields Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedSep 15, 2016
PHP min version
Downloads4K

Community Trust

Rating80/100
Number of ratings1
Active installs50
Developer Profile

Quick and Easy Post creation for ACF Relationship Fields Developer Profile

Cyril Batillat

4 plugins · 200 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Quick and Easy Post creation for ACF Relationship Fields

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/quick-and-easy-post-creation-for-acf-relationship-fields/assets/js/acf-relationship-create.min.js/wp-content/plugins/quick-and-easy-post-creation-for-acf-relationship-fields/assets/js/acf-relationship-create.js/wp-content/plugins/quick-and-easy-post-creation-for-acf-relationship-fields/assets/js/acf-relationship-create-field.min.js/wp-content/plugins/quick-and-easy-post-creation-for-acf-relationship-fields/assets/js/acf-relationship-create-field.js/wp-content/plugins/quick-and-easy-post-creation-for-acf-relationship-fields/assets/js/acf-relationship-create-iframe.min.js/wp-content/plugins/quick-and-easy-post-creation-for-acf-relationship-fields/assets/js/acf-relationship-create-iframe.js/wp-content/plugins/quick-and-easy-post-creation-for-acf-relationship-fields/assets/css/acf-relationship-create.css
Script Paths
assets/js/acf-relationship-create.min.jsassets/js/acf-relationship-create.jsassets/js/acf-relationship-create-field.min.jsassets/js/acf-relationship-create-field.jsassets/js/acf-relationship-create-iframe.min.jsassets/js/acf-relationship-create-iframe.js
Version Parameters
/assets/js/acf-relationship-create.min.js?ver=2.1/assets/js/acf-relationship-create.js?ver=2.1/assets/js/acf-relationship-create-field.min.js?ver=2.1/assets/js/acf-relationship-create-field.js?ver=2.1/assets/js/acf-relationship-create-iframe.min.js?ver=2.1/assets/js/acf-relationship-create-iframe.js?ver=2.1/assets/css/acf-relationship-create.css?ver=2.1

HTML / DOM Fingerprints

JS Globals
window.acf_relationship_create_params
FAQ

Frequently Asked Questions about Quick and Easy Post creation for ACF Relationship Fields