cbnet Favicon Security & Risk Analysis

wordpress.org/plugins/cbnet-favicon

Add a Favicon to your site. No bells or whistles; simply upload a (ICO, PNG, or GIF) file.

300 active installs v3.1 PHP + WP 3.0+ Updated Apr 14, 2016
cbnetfavicon
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is cbnet Favicon Safe to Use in 2026?

Generally Safe

Score 85/100

cbnet Favicon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "cbnet-favicon" v3.1 plugin exhibits a very strong security posture based on the provided static analysis. The absence of any identified attack surface entry points like AJAX handlers, REST API routes, shortcodes, or cron events, coupled with the lack of dangerous function usage and the exclusive use of prepared statements for SQL queries, suggests a well-secured codebase. Furthermore, the absence of any recorded vulnerabilities in its history is a significant positive indicator.

While the static analysis reveals no immediate critical security concerns, the complete lack of capability checks and nonce checks across all identified code signals is a potential area for concern. Although no explicit vulnerabilities were detected, this absence leaves the plugin open to potential privilege escalation or cross-site request forgery (CSRF) attacks if any future functionality were to be introduced or if existing, albeit currently hidden, entry points were discovered. The high percentage of properly escaped output is commendable, but the presence of some unescaped output, however small, warrants attention. Overall, the plugin appears robust and secure based on current data, but a complete absence of authorization and noncing mechanisms represents a fundamental security best practice gap.

Key Concerns

  • No capability checks
  • No nonce checks
  • Some unescaped output
Vulnerabilities
None known

cbnet Favicon Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

cbnet Favicon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

80% escaped5 total outputs
Attack Surface

cbnet Favicon Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionplugins_loadedcbnet-favicon.php:32
actionadmin_noticescbnet-favicon.php:103
actionwp_headcbnet-favicon.php:118
actionadmin_noticescbnet-favicon.php:151
actionwp_headcbnet-favicon.php:164
actionadmin_noticescbnet-favicon.php:180
actionadmin_initcbnet-favicon.php:249
actionadmin_menucbnet-favicon.php:301
Maintenance & Trust

cbnet Favicon Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedApr 14, 2016
PHP min version
Downloads39K

Community Trust

Rating100/100
Number of ratings2
Active installs300
Developer Profile

cbnet Favicon Developer Profile

Chip Bennett

7 plugins · 3K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect cbnet Favicon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cbnet-favicon/css/cbnet-favicon.css
Version Parameters
cbnet-favicon/css/cbnet-favicon.css?ver=

HTML / DOM Fingerprints

CSS Classes
cbnet-favicon-settings-page-image
FAQ

Frequently Asked Questions about cbnet Favicon