Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
WordPress.org’s October 2024 replacement of the free Advanced Custom Fields (ACF) plug-in with a fork called Secure Custom Fields (SCF) led WP Engine to accuse WordPress of taking over its plug-in “forcibly.” The practical issue for site owners was the update channel: some sites using WordPress.org updates could be switched from ACF to SCF, including automatically when plug-in auto-updates were enabled. WP Engine continued distributing its own ACF. The event did not mean that WordPress.com took over all of ACF or that every ACF installation changed.
What happened to ACF?
On October 12, 2024, WordPress.org announced that it had forked the free ACF plug-in and created Secure Custom Fields. WordPress said it was invoking point 18 of the Plugin Directory Guidelines, removing commercial upsells from the directory version and addressing a security issue. WordPress described the change as a security-driven, minimal fork.
WP Engine, which developed and maintained ACF, objected that WordPress.org had taken control of an actively maintained plug-in without the developer’s consent. It characterized the change as a forced takeover and said users could be confused about which project they were running. Those are WP Engine’s claims, not an uncontested legal finding.
Free tools Windows power users keep installed
One-click scans. No signup required.
The dispute concerned the free ACF listing and its distribution through WordPress.org’s directory and update infrastructure. It did not, by itself, transfer every ACF product or establish who owns all relevant code or marks. ACF Pro is the commercial edition distributed by the ACF/WP Engine team; SCF is a separate WordPress.org fork. WordPress.org is the directory and infrastructure at issue, not another name for WordPress.com or Automattic.
#1 Best Overall
How could an update switch a site?
WordPress said sites continuing to use WordPress.org’s update service could be offered SCF in place of ACF, and sites with plug-in auto-updates enabled could switch automatically. This was an unusual distribution-channel event: the normal update system could deliver a different project under a different name to an existing installation. It was not evidence that SCF was malware.
Sites following WP Engine’s instructions to receive ACF updates directly from the company were intended to remain on its ACF update path. WP Engine said it introduced its own update infrastructure, including the WP Engine Secure Updater, after its access to WordPress.org was restricted. At the time of the dispute, WP Engine directed affected users to its own instructions and cited ACF 6.3.8; that 2024 version number should not be treated as current guidance.
Rank #2
WordPress said the fork addressed a security issue, but the cited announcement alone does not establish the issue’s severity, exploitability or impact across ACF installations. Likewise, WP Engine’s objection about trust and authorization does not establish that SCF was malicious. The useful distinction for administrators is between a specific security claim and the broader question of who maintains a plug-in and supplies its updates.
Why the two sides disagreed
WordPress’s stated rationale was that its directory guidelines permitted a fork, that the change addressed a security concern, and that SCF removed commercial upsells. Its October announcement was written by Matt Mullenweg, a central participant in the wider dispute; that context matters when weighing the statement, though it does not by itself disprove its technical explanation.
Rank #3
WP Engine argued that ACF was actively developed, that the replacement was not approved by the ACF team, and that the action violated open-source norms and created a confusing precedent. Its use of terms such as “forcibly” and “takeover” describes its position, not a neutral determination that the action was unlawful.
The wider conflict and what changed later
The ACF fork followed a broader conflict. On September 25, 2024, Mullenweg announced that WP Engine had lost free access to WordPress.org resources, including plug-in and theme infrastructure. WordPress said it temporarily lifted the block through October 1 while WP Engine built its own infrastructure. WP Engine’s timeline says a preliminary injunction later restored access to WordPress.org and control of ACF. See WordPress.org’s access announcement, its temporary reprieve, and WP Engine’s account of the dispute and litigation.
Rank #4
Precision matters when describing the lawsuit: WP Engine’s case is against Automattic and Mullenweg, not “WordPress” as a single corporate defendant. WP Engine’s timeline reports continuing litigation activity, including a third amended complaint filed February 10, 2026, and describes several claims as having been allowed to proceed. That is a party’s summary; it should not be read as a final ruling resolving the dispute. Restoration of access also does not settle every underlying legal claim.
What ACF and SCF users should do
- Identify what is actually installed. In the WordPress dashboard, review the plug-in name, author, version and update source. Check whether it says Advanced Custom Fields or Secure Custom Fields; do not assume the site is still on ACF because that was the original installation.
- Back up before changing anything. Back up both the database and site files, then make the change on a staging copy if possible. Keep a known-good restore point.
- Choose one maintained project and update route. SCF through WordPress.org may suit a site that wants that project and directory-managed updates. ACF or ACF Pro from the ACF/WP Engine team may suit a site that depends on its product roadmap, paid features or support. Confirm the current official installation instructions rather than relying on 2024 steps.
- Test the site’s dependencies. Check custom fields, templates, blocks, forms, page builders, multilingual integrations and deployment workflows. ACF Pro-specific features deserve particular attention. The 2024 reports do not prove that ACF and SCF will remain interchangeable indefinitely.
- Review updates after the change. Confirm whether auto-updates are enabled and which repository or updater will supply future releases. Managed hosts, Composer, Git deployments and custom scripts may change how updates are delivered.
- Avoid duplicate active installations. Do not leave ACF and SCF active together unless their maintainers explicitly document a supported reason. If both are present, back up first, deactivate the unintended one, and test the site before deleting files.
- Use trusted download sources. Obtain plug-ins only from WordPress.org, the official Advanced Custom Fields site or WP Engine’s documented channel. Do not follow an unsolicited email or social-media download link.
If updates stop after changing channels, consult the current vendor instructions and check compatibility, server connectivity and update logs. Treat an unexpected plug-in identity change as a change-management issue: document it, check the source, test the site and make sure someone owns future updates.
Best Value
How to think about the choice
| Choice | May fit when | Check before choosing |
|---|---|---|
| SCF | You want the WordPress.org fork and its directory update path. | Current compatibility, maintenance, and whether your site needs ACF Pro or vendor-specific support. |
| ACF or ACF Pro | Your site depends on the ACF team’s product continuity, Pro features or support. | The current official updater and installation instructions, plus who will monitor that update route. |
Neither route is automatically right for every site. The decision is usually about feature requirements, support and update governance—not a reason by itself to change hosting providers. For a client site or security-sensitive operation, record which project is installed, its source, and who is responsible for updates.
What remains unsettled
The 2024 episode exposed how much control a plug-in directory and update service can have over software already installed on millions of sites. A fork can be technically derived from open-source code while still raising serious operational questions about notice, provenance, maintainer authority and user consent. The parties dispute those questions, and their legal conflict continued into 2026 according to WP Engine’s account. Site owners should therefore verify their own installation and update path rather than infer the present state of their site from headlines about the dispute.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

