
Advanced Custom Fields: Validated Field Security & Risk Analysis
wordpress.org/plugins/validated-field-for-acfThe Validated Field add-on for Advanced Custom Fields provides input masking and server-side validation of other field types.
Is Advanced Custom Fields: Validated Field Safe to Use in 2026?
Generally Safe
Score 85/100Advanced Custom Fields: Validated Field has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The validated-field-for-acf plugin, version 1.7.7, exhibits a concerning security posture primarily due to a significant lack of authorization checks on its AJAX endpoints. The static analysis reveals four AJAX handlers, all of which are unprotected. This represents a substantial attack surface that could allow unauthenticated users to trigger plugin functionality, potentially leading to unintended consequences or exploitation if these handlers process any user-supplied data without proper validation or sanitization. While the plugin doesn't show any known historical CVEs, this doesn't negate the immediate risks identified in the static analysis. The absence of nonces and capability checks on AJAX endpoints, coupled with a concerning finding of unsanitized paths in the taint analysis, suggests a potential for vulnerabilities like Cross-Site Request Forgery (CSRF) or even more severe issues if malicious input can be injected into these unprotected AJAX calls. The plugin's complete lack of output escaping is another critical weakness, as it opens the door to Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website's output.
Key Concerns
- Unprotected AJAX handlers
- Unsanitized paths in taint analysis
- No nonce checks
- No capability checks
- 0% properly escaped output
Advanced Custom Fields: Validated Field Security Vulnerabilities
Advanced Custom Fields: Validated Field Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Advanced Custom Fields: Validated Field Attack Surface
AJAX Handlers 4
WordPress Hooks 20
Maintenance & Trust
Advanced Custom Fields: Validated Field Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Custom Fields: Validated Field Alternatives
ACF Content Analysis for Yoast SEO
acf-content-analysis-for-yoast-seo
WordPress plugin that adds the content of all ACF fields to the Yoast SEO score analysis.
Advanced Custom Fields: Font Awesome Field
advanced-custom-fields-font-awesome
Adds a new 'Font Awesome Icon' field to the popular Advanced Custom Fields plugin.
Table Field Add-on for ACF and SCF
advanced-custom-fields-table-field
A Table Field Add-on for the Advanced Custom Fields and Secure Custom Fields Plugin.
ACF: Better Search
acf-better-search
This plugin adds to default WordPress search engine the ability to search by content from selected fields of Advanced Custom Fields plugin.
WP All Import – Import Add-On for ACF
csv-xml-import-for-acf
Drag & drop to import any CSV, Excel, XML, or Google Sheets file into Advanced Custom Fields. Supports repeaters, flexible content, galleries, and …
Advanced Custom Fields: Validated Field Developer Profile
1 plugin · 200 total installs
How We Detect Advanced Custom Fields: Validated Field
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/validated-field-for-acf/css/acf-validated-field.css/wp-content/plugins/validated-field-for-acf/js/acf-validated-field.js/wp-content/plugins/validated-field-for-acf/js/acf-validated-field.min.js/wp-content/plugins/validated-field-for-acf/js/acf-validated-field.js/wp-content/plugins/validated-field-for-acf/js/acf-validated-field.min.jsvalidated-field-for-acf/css/acf-validated-field.css?ver=validated-field-for-acf/js/acf-validated-field.js?ver=validated-field-for-acf/js/acf-validated-field.min.js?ver=HTML / DOM Fingerprints
acf-validated-fielddata-maskdata-mask-autocleardata-mask-placeholderdata-functiondata-patterndata-message+4 moreajaxurl