Admin Columns – Icons Add-on Security & Risk Analysis
wordpress.org/plugins/admin-columns-icons-addonUse icons instead of text labels in column headers on post, user, media and other admin pages. Extension for Admin Columns.
Is Admin Columns – Icons Add-on Safe to Use in 2026?
Generally Safe
Score 85/100Admin Columns – Icons Add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "admin-columns-icons-addon" v1.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of known CVEs, a clean vulnerability history, and the complete absence of critical or high severity taint flows are positive indicators. Furthermore, the code adheres to good practices by utilizing prepared statements for all SQL queries and properly escaping the vast majority of output. The attack surface appears minimal, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that are accessible without authentication.
However, a few areas warrant attention. The lack of any capability checks and nonce checks, particularly given the potential for file operations, raises a concern. While the static analysis shows no direct evidence of vulnerabilities related to these omissions, it suggests a potential weakness that could be exploited if the plugin's functionality were to evolve or interact with other components in unexpected ways. The single file operation, without further context on its nature and associated checks, also presents a minor point of scrutiny. Overall, the plugin is secure against known threats and common vulnerabilities, but a review of its authorization and input validation mechanisms, especially concerning file operations, would further solidify its security.
The plugin's history of zero vulnerabilities and zero unpatched CVEs suggests a development team that is either very diligent or has not yet been targeted effectively. The lack of critical or high severity findings in the taint analysis is also a very positive sign. The limited attack surface and secure coding practices for SQL and output escaping are commendable. The primary area for improvement lies in strengthening the checks around potential privileged operations, like file operations, to ensure robust defense against future, as-yet-undiscovered, attack vectors.
Key Concerns
- No capability checks implemented
- No nonce checks implemented
- File operations present without clear checks
- Output escaping not 100% proper
Admin Columns – Icons Add-on Security Vulnerabilities
Admin Columns – Icons Add-on Code Analysis
Output Escaping
Admin Columns – Icons Add-on Attack Surface
WordPress Hooks 7
Maintenance & Trust
Admin Columns – Icons Add-on Maintenance & Trust
Maintenance Signals
Community Trust
Admin Columns – Icons Add-on Alternatives
Admin Columns for ACF Fields
admin-columns-for-acf-fields
Allows you to enable columns for your ACF fields in post and taxonomy overviews (e.g. "All Posts") in the Wordpress admin backend.
WP Adminify – White Label WordPress, Admin Menu Editor, Login Customizer
adminify
Transform your WordPress admin into a fully white-labeled, organized client dashboard. Customize, Dark mode, Secure, Boost productivity, and more.
Admin Slug Column
admin-slug-column
Adds a URL path column to all admin post type edit screens. Works with posts, pages, and any custom post type including WooCommerce products.
Add Featured Image Column
add-featured-image-column
This plugin adds a featured image column to any post type which supports featured images. See which posts have a featured image at a glance!
Post Admin Word Count
post-admin-word-count
Adds a sortable word count column to the admin post list for all public post types. Efficient, lightweight and built with modern best practices.
Admin Columns – Icons Add-on Developer Profile
7 plugins · 2K total installs
How We Detect Admin Columns – Icons Add-on
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/admin-columns-icons-addon/assets/css/admin/cpac-settings.css/wp-content/plugins/admin-columns-icons-addon/assets/js/admin/cpac-settings.js/wp-content/plugins/admin-columns-icons-addon/assets/js/admin/cpac-settings.jsadmin-columns-icons-addon/assets/css/admin/cpac-settings.css?ver=admin-columns-icons-addon/assets/js/admin/cpac-settings.js?ver=HTML / DOM Fingerprints
cpacic-label-icon-dashiconcpacic-label-icon-customcpacic-label-icon-attachmentcpapic-current-icondata-columndata-dashicon