
Support For Icomoon with Advanced Custom Fields Security & Risk Analysis
wordpress.org/plugins/acf-icomoonAdd a field to select icons from a selection.json file generated by IcoMoon
Is Support For Icomoon with Advanced Custom Fields Safe to Use in 2026?
Generally Safe
Score 100/100Support For Icomoon with Advanced Custom Fields has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'acf-icomoon' plugin version 4.0.16 exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the code's adherence to prepared statements for all SQL queries is a commendable practice that prevents common SQL injection vulnerabilities. The plugin also demonstrates an effort to sanitize output, with a majority of outputs being properly escaped. However, the fact that only 56% of outputs are properly escaped indicates a potential for Cross-Site Scripting (XSS) vulnerabilities if the unescaped outputs are user-controllable or contain sensitive data.
The taint analysis shows no critical or high-severity flows, which is positive. The single file operation and lack of external HTTP requests reduce the potential for file manipulation or server-side request forgery (SSRF) issues. The absence of recorded vulnerabilities, including CVEs, further reinforces the perception of a secure plugin. Despite the positive findings, the lack of any nonce checks or capability checks, coupled with the partial output escaping, represents the primary areas of concern. While the attack surface is currently minimal, any future additions to functionality without proper authentication and authorization checks could introduce significant risks.
Key Concerns
- Partial output escaping (56%)
- No nonce checks
- No capability checks
Support For Icomoon with Advanced Custom Fields Security Vulnerabilities
Support For Icomoon with Advanced Custom Fields Code Analysis
Output Escaping
Support For Icomoon with Advanced Custom Fields Attack Surface
WordPress Hooks 4
Maintenance & Trust
Support For Icomoon with Advanced Custom Fields Maintenance & Trust
Maintenance Signals
Community Trust
Support For Icomoon with Advanced Custom Fields Alternatives
ACF Content Analysis for Yoast SEO
acf-content-analysis-for-yoast-seo
WordPress plugin that adds the content of all ACF fields to the Yoast SEO score analysis.
Advanced Custom Fields: Font Awesome Field
advanced-custom-fields-font-awesome
Adds a new 'Font Awesome Icon' field to the popular Advanced Custom Fields plugin.
Table Field Add-on for ACF and SCF
advanced-custom-fields-table-field
A Table Field Add-on for the Advanced Custom Fields and Secure Custom Fields Plugin.
ACF: Better Search
acf-better-search
This plugin adds to default WordPress search engine the ability to search by content from selected fields of Advanced Custom Fields plugin.
WP All Import – Import Add-On for ACF
csv-xml-import-for-acf
Drag & drop to import any CSV, Excel, XML, or Google Sheets file into Advanced Custom Fields. Supports repeaters, flexible content, galleries, and …
Support For Icomoon with Advanced Custom Fields Developer Profile
1 plugin · 1K total installs
How We Detect Support For Icomoon with Advanced Custom Fields
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/acf-icomoon/assets/css/icomoon.cssacf-icomoon/style.css?ver=HTML / DOM Fingerprints
vii-icomoonvii-icomoon__hidden-inputvii-icomoon__custom-fieldvii-icomoon__custom-field-innervii-icomoon__custom-field-resultvii-icomoon__icon-svgvii-icomoon__icon-namevii-icomoon__custom-field-removedata-icomoon-inputdata-icomoon-appdata-icomoon-selecteddata-icomoon-iconsdata-icomoon-popup-triggervii_acf_icomoon_empty_json