shouldiuse.io

VERDICT

Should I use Advanced Custom Fields (ACF)?

WordPress plugin for adding custom fields to content, owned by WP Engine - advancedcustomfields.com

Depends. Buy if you're a developer building structured content on WordPress — ACF is the category default with a huge ecosystem. Skip it if you don't code or don't use WordPress, and weigh the pricing hikes plus the 2024 WordPress.org takeover drama.

Confidence

Medium. Based on 40+ public sources: Reddit threads, G2, security databases (Wordfence, Patchstack, NVD, OpenCVE), and official ACF pages. Snippets truncated; no exact PRO prices quoted in sources.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

$0

ACF (free)

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
ACF PROPaid yearly license, per site (see site)

Best for

  • WordPress developers
  • Agencies building client sites
  • Structured-content sites (recipes, reviews, directories)
  • Custom post-type-heavy projects

Not for

  • Anything outside WordPress — it simply doesn't apply
  • Non-technical site owners wanting drag-and-drop editing
  • Simple blogs with no structured content — plain WordPress is enough
  • Teams unwilling to navigate the WP Engine vs fork mess

Gotchas - check before you buy

high

Two competing versions (WP Engine's ACF vs fork) create update and support confusion

high

History of serious vulnerabilities (XSS, RCE, file upload) — patch immediately on release

medium

Per-site licensing adds up; multiple Reddit threads document steep price increases

medium

Deactivating or deleting ACF after building fields can break your content

Pros and cons

Pros

  • De facto standard for WordPress custom fields, with deep ecosystem and docs
  • Free core version available on
  • G2 reviewers consistently praise the plugin
  • Proven at scale, including a UN refugee agency case study
  • Vendor ships prompt, dedicated security releases

Cons

  • Pricing hikes users call 'ouch' and 'prohibitively expensive'
  • forcibly took over and forked the plugin in 2024
  • 15 tracked CVEs, including issues affecting ~100,000 sites
  • Requires developer skills; not plug-and-play for editors
  • Users feel forced to pick between competing plugin versions

Sources & method

Analyzed 9/26/2026 - 10 sources - 15 tracked CVEs with recurring XSS and RCE issues affecting hundreds of thousands of sites; vendor issues frequent security patches.

official x3review x3security x2news x2
  • Reflected XSS affecting ~2 million sites, Patchstack disclosed reflected XSS across ACF plugins in May 2023.
  • Arbitrary file upload in ACF Pro 5.12.2, Acunetix documented an arbitrary file upload vulnerability exploitable by attackers.
  • Remote code execution affecting ~100,000 sites, Reddit reports 100,000 WordPress sites affected by a remote code execution issue.
  • Privilege escalation in companion plugin ACF Extended, Wordfence reported ~100,000 sites affected via the third-party ACF Extended plugin, Jan 2026 — not core ACF itself.

Key stats

  • Value for money: 2/5

    Rating

  • $0

    Starting price

  • 10

    Sources

  • Analyzed

  • Value for money: 2/5. Users call price hikes 'ouch' and 'prohibitively expensive'
  • Ease of use: 4/5. G2 reviewers consistently praise it
  • Feature depth: 5/5. Category standard: blocks, repeaters, huge ecosystem
  • Support quality: 3/5. Free official forums and support advertised
  • Security posture: 2/5. Recurring CVEs, though vendor patches promptly
  • Yes Free version On WordPress.org
  • 15 Tracked CVEs OpenCVE database
  • ~2M Sites hit by 2023 XSS Patchstack disclosure, May 2023
  • WP Engine Owner Central figure in 2024 fork dispute

Pricing

ACF (free)

$0

  • Core custom fields
  • Community support via WordPress.org

ACF PRO

Paid yearly license, per site (see site)

  • Advanced field types
  • ACF Blocks
  • Priority support

Security

15 tracked CVEs with recurring XSS and RCE issues affecting hundreds of thousands of sites; vendor issues frequent security patches.

  • Reflected XSS affecting ~2 million sitesPatchstack disclosed reflected XSS across ACF plugins in May 2023.⁷
  • Arbitrary file upload in ACF Pro 5.12.2Acunetix documented an arbitrary file upload vulnerability exploitable by attackers.
  • Remote code execution affecting ~100,000 sitesReddit reports 100,000 WordPress sites affected by a remote code execution issue.
  • Privilege escalation in companion plugin ACF ExtendedWordfence reported ~100,000 sites affected via the third-party ACF Extended plugin, Jan 2026 — not core ACF itself.

What users say

Developers praise ACF's flexibility and ecosystem but repeatedly gripe about price hikes and the WordPress.org takeover saga.

Companies that use it

  • UNHCR (UN Refugee Agency)⁹
  • Noiza (agency that built the UNHCR site)⁹
Full analysis

Based on 40+ public sources: Reddit threads, G2, security databases (Wordfence, Patchstack, NVD, OpenCVE), and official ACF pages. Snippets truncated; no exact PRO prices quoted in sources.

WordPress's default custom-fields plugin; essential for devs, pointless outside WP, with pricing hikes and fork drama.

Methodology

Based on 40+ public sources: Reddit threads, G2, security databases (Wordfence, Patchstack, NVD, OpenCVE), and official ACF pages. Snippets truncated; no exact PRO prices quoted in sources.

Sources

  1. official
  2. ACF PRO pricing pageadvancedcustomfields.com
    official
  3. review
  4. review
  5. news
  6. review
  7. security
  8. security
  9. UNHCR case study – ACF blogadvancedcustomfields.com
    official
  10. news

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.