Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

WordPress.org Forked ACF Into Secure Custom Fields in 2024: What Users Need to Know

WordPress.org’s 2024 fork of free ACF created Secure Custom Fields, but original ACF remained available separately. Here’s how to identify your plugin and updates.
From TheFinanceBase Team6 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

On October 12, 2024, WordPress.org replaced the free Advanced Custom Fields (ACF) plugin listing with a fork called Secure Custom Fields (SCF). The move affected the version distributed through WordPress.org; it did not mean WordPress acquired all of WP Engine’s ACF business. The original ACF team continued distributing ACF separately, and ACF PRO updates remained tied to the ACF website and license system.

For site owners, the practical question is which plugin and update source their site uses. SCF and original ACF are separate paths, and a plugin-name change alone does not establish that a site’s field data was lost. Check the installed plugin, its update source, and compatibility before making changes.

What WordPress.org changed

WordPress.org announced on October 12, 2024, that its security team was invoking point 18 of the Plugin Directory Guidelines to fork the free ACF plugin and distribute the fork as Secure Custom Fields. WordPress described the changes as removing commercial upsells and addressing a security issue. Those are WordPress’s stated reasons, not an independently established finding about the original plugin. WordPress’s announcement

The precise description matters: WordPress.org changed what it distributed through its plugin directory. That is different from saying WordPress bought ACF, took ownership of every ACF product, or seized WP Engine’s entire codebase. The original ACF team continued to distribute its plugin through its own update infrastructure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How ACF became part of the WP Engine dispute

The fork came during a wider conflict involving Matt Mullenweg, Automattic, WordPress.org, the WordPress security team, and WP Engine. They are related participants in the dispute, but they are not interchangeable entities. The disagreement involved WordPress.org access, trademark use, contributions to the project, and other matters; it was not simply a disagreement about one plugin’s security.

  1. Late September 2024: WordPress.org blocked WP Engine’s access to its infrastructure. WordPress.org described the ban and later announced a reprieve. WordPress.org’s ban announcement and reprieve announcement
  2. October 2024: The access dispute affected WP Engine’s ability to use the normal WordPress.org distribution route for updates to plugins hosted there. WP Engine set up an alternative update mechanism for free ACF, and ACF published instructions for continuing to update it. ACF’s update guidance from the dispute
  3. October 12, 2024: WordPress.org announced SCF, its fork of the free ACF listing. WordPress’s SCF announcement

WordPress said its intervention addressed a security problem and removed commercial upsells. The original ACF/WP Engine team objected to the action and characterized it as a forcible takeover of its plugin. The existence and scope of the governance dispute should not be confused with a settled conclusion about the legality of the action. TechCrunch’s report, published October 12, 2024

What a fork means—and what changed for users

A fork begins with an existing codebase and is maintained separately. It may retain APIs, database structures, and conventions that help existing sites continue to work, while later diverging in features, security practices, release cadence, governance, or licensing. WordPress argued that forking is a normal part of open-source software. WordPress’s explanation of forking

WordPress.org said sites still using the directory’s update service could receive SCF through the usual update process; sites with automatic updates enabled could be switched automatically. Sites that followed ACF/WP Engine’s instructions to use the separate update path could continue receiving original ACF instead. The directory action did not, by itself, mean custom-field values were deleted. ACF’s update instructions describe replacing plugin files while preserving fields and settings, but any production plugin change warrants a backup and a staging test. ACF’s update guide

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Identify what your site is running

  1. In WordPress, open Plugins → Installed Plugins and note the plugin name, version, and author.
  2. Check where updates are offered. SCF uses the WordPress.org plugin update path; original ACF uses ACF’s update infrastructure. ACF PRO updates are provided through the ACF website, with an active license required for automatic licensed updates.
  3. Do not rely on the name alone. Confirm the plugin’s version and update source, and check your host or deployment process if updates are managed outside the WordPress dashboard.

SCF is the WordPress.org-distributed continuation of the free ACF codebase. Original ACF remains available from the ACF team. They are distinct update paths, not two labels for one centrally updated plugin. SCF’s WordPress.org listing and ACF’s update guide

Choose an update path that fits the site

If you use SCF

Keep it updated through WordPress.org and test important site behavior after updates, especially if your site depends on custom integrations. SCF’s installation handbook lists WordPress 6.2 or later and PHP 7.4 or later as requirements, with at least 40 MB of WordPress memory and 64 MB recommended. SCF installation requirements

If you want original ACF

Use the official ACF distribution and verify that updates appear from the intended source. ACF says versions 6.3.8 and later, as well as ACF installations hosted on WP Engine or Flywheel, can update through the WordPress Plugins screen when the appropriate update source is configured. Older versions may need a one-time manual installation before normal updates resume. ACF’s manual process is to download its ZIP, open Plugins → Add New Plugin → Upload Plugin, upload the file, approve overwriting the existing plugin, and then verify the installation and future updates. ACF’s update instructions

If you use ACF PRO

ACF says PRO updates continue through its website. Automatic licensed updates require an active license. Check the license and update status separately from the free plugin’s distribution path. ACF’s update guide

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you manage a production site

  • Back up files and the database, and test the intended update path on staging.
  • After changing or updating the plugin, inspect field groups, repeaters, flexible content, options pages, custom blocks, custom post types, and frontend templates that depend on fields.
  • Test REST/API behavior and integrations with page builders, multilingual plugins, themes, and other extensions.
  • Avoid running SCF and original ACF simultaneously unless the relevant vendor documentation explicitly supports that setup.
  • Use only the official WordPress.org SCF listing or the official ACF download source, not an arbitrary ZIP mirror.

SCF began as a fork, so compatibility may be substantial, but that does not establish that every add-on, deployment workflow, or future release is interchangeable. The specific theme, plugin versions, and implementation determine what needs testing. WordPress.org support discussion of ACF and SCF

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

SCF’s current WordPress.org status

When checked on August 18, 2026, the WordPress.org listing showed SCF version 6.9.3, more than 80,000 active installations, a WordPress requirement of 6.2 or later, PHP 7.4 or later, compatibility listed through WordPress 7.0.2, and a 4.8-out-of-5-star rating. These are changeable directory figures, not permanent guarantees of compatibility. SCF’s WordPress.org listing

Why the intervention remains a governance question

The episode exposed the practical power of WordPress.org’s distribution channel: a directory listing can be a major route for plugin installation and updates, and the directory’s rules give its administrators broad powers to remove, disable, modify, or fork plugins in the interest of public safety. That channel power is distinct from questions of copyright, open-source license rights, and ownership of the original project.

WordPress described the action as rare and unusual. The competing concerns are whether directory administrators can act quickly to protect users and whether creators and users can rely on predictable stewardship of an actively maintained project. The episode raises a precedent concern, but it does not establish that similar takeovers are routine or resolve the legal dispute.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When another custom-fields tool makes sense

Most ACF users do not need to migrate just because SCF exists. If evaluating alternatives for a new project or a deliberate migration, compare APIs, field types, add-ons, licensing, update source, support, and the amount of template or application code that would need rewriting. Pods, Meta Box, Toolset, and Carbon Fields are other options, but they are not automatically drop-in replacements for ACF or SCF.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.