Support For Icomoon with Advanced Custom Fields Security & Risk Analysis

wordpress.org/plugins/acf-icomoon

Add a field to select icons from a selection.json file generated by IcoMoon

1K active installs v4.0.16 PHP 7.2+ WP 6.8.2+ Updated Aug 20, 2025
acfadvanced-custom-fieldsicomoon
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Support For Icomoon with Advanced Custom Fields Safe to Use in 2026?

Generally Safe

Score 100/100

Support For Icomoon with Advanced Custom Fields has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The 'acf-icomoon' plugin version 4.0.16 exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the code's adherence to prepared statements for all SQL queries is a commendable practice that prevents common SQL injection vulnerabilities. The plugin also demonstrates an effort to sanitize output, with a majority of outputs being properly escaped. However, the fact that only 56% of outputs are properly escaped indicates a potential for Cross-Site Scripting (XSS) vulnerabilities if the unescaped outputs are user-controllable or contain sensitive data.

The taint analysis shows no critical or high-severity flows, which is positive. The single file operation and lack of external HTTP requests reduce the potential for file manipulation or server-side request forgery (SSRF) issues. The absence of recorded vulnerabilities, including CVEs, further reinforces the perception of a secure plugin. Despite the positive findings, the lack of any nonce checks or capability checks, coupled with the partial output escaping, represents the primary areas of concern. While the attack surface is currently minimal, any future additions to functionality without proper authentication and authorization checks could introduce significant risks.

Key Concerns

  • Partial output escaping (56%)
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Support For Icomoon with Advanced Custom Fields Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Support For Icomoon with Advanced Custom Fields Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

56% escaped9 total outputs
Attack Surface

Support For Icomoon with Advanced Custom Fields Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionvc_before_initacf-icomoon.php:47
actionadmin_noticesacf-icomoon.php:56
actionwp_footeracf-icomoon.php:72
actionacf/include_field_typesincludes\acf-icomoon.php:10
Maintenance & Trust

Support For Icomoon with Advanced Custom Fields Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 20, 2025
PHP min version7.2
Downloads10K

Community Trust

Rating100/100
Number of ratings1
Active installs1K
Developer Profile

Support For Icomoon with Advanced Custom Fields Developer Profile

ViiVue

1 plugin · 1K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Support For Icomoon with Advanced Custom Fields

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/acf-icomoon/assets/css/icomoon.css
Version Parameters
acf-icomoon/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
vii-icomoonvii-icomoon__hidden-inputvii-icomoon__custom-fieldvii-icomoon__custom-field-innervii-icomoon__custom-field-resultvii-icomoon__icon-svgvii-icomoon__icon-namevii-icomoon__custom-field-remove
Data Attributes
data-icomoon-inputdata-icomoon-appdata-icomoon-selecteddata-icomoon-iconsdata-icomoon-popup-trigger
JS Globals
vii_acf_icomoon_empty_json
FAQ

Frequently Asked Questions about Support For Icomoon with Advanced Custom Fields