All In One Favicon Security & Risk Analysis
wordpress.org/plugins/all-in-one-faviconEasily add a Favicon to your site and the WordPress admin pages. Complete with upload functionality. Supports all three Favicon types (ico,png,gif).
Is All In One Favicon Safe to Use in 2026?
Mostly Safe
Score 84/100All In One Favicon is generally safe to use though it hasn't been updated recently. 2 past CVEs were resolved.
The 'all-in-one-favicon' plugin version 4.8 presents a mixed security posture. While it demonstrates some good practices, such as using prepared statements for all SQL queries and performing capability checks, significant concerns remain. The presence of two unprotected AJAX handlers creates a considerable attack surface, increasing the risk of unauthorized actions. Furthermore, the use of dangerous functions like `create_function` and `unserialize` raises red flags for potential code injection vulnerabilities. Taint analysis indicates two high-severity flows with unsanitized paths, suggesting a potential for directory traversal or similar exploits. The plugin's vulnerability history, despite having no currently unpatched CVEs, reveals a pattern of medium-severity vulnerabilities, including path traversal and cross-site scripting, in the past. This history, combined with the identified code signals and attack surface, indicates a need for caution and potential updates.
Key Concerns
- Unprotected AJAX handlers
- Use of dangerous 'create_function'
- Use of dangerous 'unserialize'
- High severity unsanitized path flows (2)
- Low percentage of properly escaped output
- History of medium vulnerabilities (2)
All In One Favicon Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
All In One Favicon <= 4.7 - Authenticated(Admin+) Directory Traversal
All In One Favicon <= 4.6 - Authenticated (Admin+) Stored Cross-Site Scripting
All In One Favicon Release Timeline
All In One Favicon Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
All In One Favicon Attack Surface
AJAX Handlers 2
WordPress Hooks 12
Maintenance & Trust
All In One Favicon Maintenance & Trust
Maintenance Signals
Community Trust
All In One Favicon Alternatives
PWD WP Favicon
pwd-wp-favicon
This plugin allows you to upload a custom favicon & Apple touch icon for your website and your WordPress Dashboard using API customizer.
Site Icon Pro
site-icon-pro
Site Icon Pro gives you full control over the exact icons and HTML used to display the favicon and app icons on your Wordpress site!
Redux Framework
redux-framework
Redux is a simple, truly extensible, and fully responsive options framework for WordPress themes and plugins. It ships with an integrated demo.
Cryout Serious Theme Settings
cryout-theme-settings
This plugin is designed to inter-operate with our Mantra, Parabola, Tempera, Nirvana themes to enable their settings pages.
WP Updates Notifier
wp-updates-notifier
Sends email to notify you if there are any updates for your WordPress site. Can notify about core, plugin and theme updates.
All In One Favicon Developer Profile
8 plugins · 111K total installs
How We Detect All In One Favicon
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/all-in-one-favicon/css//wp-content/plugins/all-in-one-favicon/js//wp-content/plugins/all-in-one-favicon/images//wp-content/plugins/all-in-one-favicon/js/aio-favicon-backend.js/wp-content/plugins/all-in-one-favicon/js/aio-favicon-frontend.js/wp-content/plugins/all-in-one-favicon/js/aio-favicon-debug.jsall-in-one-favicon/css/aio-favicon-backend.css?ver=all-in-one-favicon/css/aio-favicon-frontend.css?ver=all-in-one-favicon/js/aio-favicon-backend.js?ver=all-in-one-favicon/js/aio-favicon-frontend.js?ver=all-in-one-favicon/js/aio-favicon-debug.js?ver=HTML / DOM Fingerprints
aio-favicon-settings-groupaio-favicon-upload-areaaio-favicon-image-previewaio-favicon-delete-buttonaio-favicon-save-buttonaio-favicon-cancel-buttonaio-favicon-tabsaio-favicon-tab-content<!-- START: All in one Favicon --><!-- END: All in one Favicon --><!-- All in one Favicon Admin Settings --><!-- All in one Favicon Front End Settings -->data-aio-favicon-actiondata-aio-favicon-typewindow.aioFaviconSettingswindow.aioFaviconDefaultSettingswindow.aioFaviconBackendMapwindow.aioFaviconFrontendMapvar aioFaviconSettingsvar aioFaviconDefaultSettings+2 more