On October 12, 2024, WordPress.org replaced the free Advanced Custom Fields (ACF) plugin listing with a fork called Secure Custom Fields (SCF). The move affected the version distributed through WordPress.org; it did not mean WordPress acquired all of WP Engine’s ACF business. The original ACF team continued distributing ACF separately, and ACF PRO updates remained tied to the ACF website and license system.
For site owners, the practical question is which plugin and update source their site uses. SCF and original ACF are separate paths, and a plugin-name change alone does not establish that a site’s field data was lost. Check the installed plugin, its update source, and compatibility before making changes.
What WordPress.org changed
WordPress.org announced on October 12, 2024, that its security team was invoking point 18 of the Plugin Directory Guidelines to fork the free ACF plugin and distribute the fork as Secure Custom Fields. WordPress described the changes as removing commercial upsells and addressing a security issue. Those are WordPress’s stated reasons, not an independently established finding about the original plugin. WordPress’s announcement
The precise description matters: WordPress.org changed what it distributed through its plugin directory. That is different from saying WordPress bought ACF, took ownership of every ACF product, or seized WP Engine’s entire codebase. The original ACF team continued to distribute its plugin through its own update infrastructure.
Recommended Free Tools
#1 Best Overall
How ACF became part of the WP Engine dispute
The fork came during a wider conflict involving Matt Mullenweg, Automattic, WordPress.org, the WordPress security team, and WP Engine. They are related participants in the dispute, but they are not interchangeable entities. The disagreement involved WordPress.org access, trademark use, contributions to the project, and other matters; it was not simply a disagreement about one plugin’s security.
- Late September 2024: WordPress.org blocked WP Engine’s access to its infrastructure. WordPress.org described the ban and later announced a reprieve. WordPress.org’s ban announcement and reprieve announcement
- October 2024: The access dispute affected WP Engine’s ability to use the normal WordPress.org distribution route for updates to plugins hosted there. WP Engine set up an alternative update mechanism for free ACF, and ACF published instructions for continuing to update it. ACF’s update guidance from the dispute
- October 12, 2024: WordPress.org announced SCF, its fork of the free ACF listing. WordPress’s SCF announcement
WordPress said its intervention addressed a security problem and removed commercial upsells. The original ACF/WP Engine team objected to the action and characterized it as a forcible takeover of its plugin. The existence and scope of the governance dispute should not be confused with a settled conclusion about the legality of the action. TechCrunch’s report, published October 12, 2024
What a fork means—and what changed for users
A fork begins with an existing codebase and is maintained separately. It may retain APIs, database structures, and conventions that help existing sites continue to work, while later diverging in features, security practices, release cadence, governance, or licensing. WordPress argued that forking is a normal part of open-source software. WordPress’s explanation of forking
WordPress.org said sites still using the directory’s update service could receive SCF through the usual update process; sites with automatic updates enabled could be switched automatically. Sites that followed ACF/WP Engine’s instructions to use the separate update path could continue receiving original ACF instead. The directory action did not, by itself, mean custom-field values were deleted. ACF’s update instructions describe replacing plugin files while preserving fields and settings, but any production plugin change warrants a backup and a staging test. ACF’s update guide
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
Identify what your site is running
- In WordPress, open Plugins → Installed Plugins and note the plugin name, version, and author.
- Check where updates are offered. SCF uses the WordPress.org plugin update path; original ACF uses ACF’s update infrastructure. ACF PRO updates are provided through the ACF website, with an active license required for automatic licensed updates.
- Do not rely on the name alone. Confirm the plugin’s version and update source, and check your host or deployment process if updates are managed outside the WordPress dashboard.
SCF is the WordPress.org-distributed continuation of the free ACF codebase. Original ACF remains available from the ACF team. They are distinct update paths, not two labels for one centrally updated plugin. SCF’s WordPress.org listing and ACF’s update guide
Choose an update path that fits the site
If you use SCF
Keep it updated through WordPress.org and test important site behavior after updates, especially if your site depends on custom integrations. SCF’s installation handbook lists WordPress 6.2 or later and PHP 7.4 or later as requirements, with at least 40 MB of WordPress memory and 64 MB recommended. SCF installation requirements
Rank #4
If you want original ACF
Use the official ACF distribution and verify that updates appear from the intended source. ACF says versions 6.3.8 and later, as well as ACF installations hosted on WP Engine or Flywheel, can update through the WordPress Plugins screen when the appropriate update source is configured. Older versions may need a one-time manual installation before normal updates resume. ACF’s manual process is to download its ZIP, open Plugins → Add New Plugin → Upload Plugin, upload the file, approve overwriting the existing plugin, and then verify the installation and future updates. ACF’s update instructions
If you use ACF PRO
ACF says PRO updates continue through its website. Automatic licensed updates require an active license. Check the license and update status separately from the free plugin’s distribution path. ACF’s update guide
Best Value
If you manage a production site
- Back up files and the database, and test the intended update path on staging.
- After changing or updating the plugin, inspect field groups, repeaters, flexible content, options pages, custom blocks, custom post types, and frontend templates that depend on fields.
- Test REST/API behavior and integrations with page builders, multilingual plugins, themes, and other extensions.
- Avoid running SCF and original ACF simultaneously unless the relevant vendor documentation explicitly supports that setup.
- Use only the official WordPress.org SCF listing or the official ACF download source, not an arbitrary ZIP mirror.
SCF began as a fork, so compatibility may be substantial, but that does not establish that every add-on, deployment workflow, or future release is interchangeable. The specific theme, plugin versions, and implementation determine what needs testing. WordPress.org support discussion of ACF and SCF
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.SCF’s current WordPress.org status
When checked on August 18, 2026, the WordPress.org listing showed SCF version 6.9.3, more than 80,000 active installations, a WordPress requirement of 6.2 or later, PHP 7.4 or later, compatibility listed through WordPress 7.0.2, and a 4.8-out-of-5-star rating. These are changeable directory figures, not permanent guarantees of compatibility. SCF’s WordPress.org listing
Why the intervention remains a governance question
The episode exposed the practical power of WordPress.org’s distribution channel: a directory listing can be a major route for plugin installation and updates, and the directory’s rules give its administrators broad powers to remove, disable, modify, or fork plugins in the interest of public safety. That channel power is distinct from questions of copyright, open-source license rights, and ownership of the original project.
WordPress described the action as rare and unusual. The competing concerns are whether directory administrators can act quickly to protect users and whether creators and users can rely on predictable stewardship of an actively maintained project. The episode raises a precedent concern, but it does not establish that similar takeovers are routine or resolve the legal dispute.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →When another custom-fields tool makes sense
Most ACF users do not need to migrate just because SCF exists. If evaluating alternatives for a new project or a deliberate migration, compare APIs, field types, add-ons, licensing, update source, support, and the amount of template or application code that would need rewriting. Pods, Meta Box, Toolset, and Carbon Fields are other options, but they are not automatically drop-in replacements for ACF or SCF.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




