
CMB2 Field Type: Font Awesome Security & Risk Analysis
wordpress.org/plugins/cmb2-field-type-font-awesomeFont Awesome icon selector for powerful custom metabox generator CMB2
Is CMB2 Field Type: Font Awesome Safe to Use in 2026?
Generally Safe
Score 85/100CMB2 Field Type: Font Awesome has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'cmb2-field-type-font-awesome' v1.4 exhibits a generally strong security posture based on the provided static analysis. There are no identified vulnerabilities in its history, and the code analysis reveals a clean slate regarding dangerous functions, SQL injection risks (all queries use prepared statements), file operations, and external HTTP requests. The absence of any taint flows with unsanitized paths further strengthens this positive assessment, indicating no readily apparent ways for user-supplied data to compromise the system.
However, a significant concern arises from the complete lack of output escaping. With one total output identified and 0% properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic content generated by this plugin that is not meticulously sanitized before being displayed to users could be exploited by attackers. Furthermore, the absence of nonce checks and capability checks across all entry points (which, while currently zero, could expand if the plugin were updated to include them) suggests a potential for privilege escalation or unauthorized actions if new entry points are introduced without proper security measures.
While the plugin's current lack of known vulnerabilities and clean historical record are positive indicators, the critical oversight in output escaping presents a tangible and immediate risk. The strengths lie in its careful handling of database interactions and avoidance of risky functions. The main weakness is the unaddressed XSS potential. Future development should prioritize robust output escaping to mitigate this significant vulnerability.
Key Concerns
- Output escaping is not properly implemented
- No nonce checks on entry points
- No capability checks on entry points
CMB2 Field Type: Font Awesome Security Vulnerabilities
CMB2 Field Type: Font Awesome Code Analysis
Output Escaping
CMB2 Field Type: Font Awesome Attack Surface
WordPress Hooks 2
Maintenance & Trust
CMB2 Field Type: Font Awesome Maintenance & Trust
Maintenance Signals
Community Trust
CMB2 Field Type: Font Awesome Alternatives
WP Rollback – Rollback Plugins and Themes
wp-rollback
Rollback (or forward) any WordPress.org plugin, theme, or block like a boss.
Advanced Custom Fields: Font Awesome Field
advanced-custom-fields-font-awesome
Adds a new 'Font Awesome Icon' field to the popular Advanced Custom Fields plugin.
Download Plugin
download-plugin
Download any plugin from your WordPress admin panel's Plugins page by just one click! Now, download themes, users, blog posts, pages, custom post …
Advanced Automatic Updates
automatic-updater
Adds extra options to WordPress' built-in Automatic Updates feature.
Stratum Widgets for Elementor
stratum
20+ Premium widgets for Elementor, including Advanced Slider, Instagram, Google Maps, Advanced Accordion, Post Grid.
CMB2 Field Type: Font Awesome Developer Profile
6 plugins · 610 total installs
How We Detect CMB2 Field Type: Font Awesome
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cmb2-field-type-font-awesome/css/faws/css/font-awesome.min.css/wp-content/plugins/cmb2-field-type-font-awesome/css/css/base/jquery.fonticonpicker.min.css/wp-content/plugins/cmb2-field-type-font-awesome/css/css/themes/grey-theme/jquery.fonticonpicker.grey.min.css/wp-content/plugins/cmb2-field-type-font-awesome/js/jquery.fonticonpicker.min.js/wp-content/plugins/cmb2-field-type-font-awesome/js/main.jshttps://use.fontawesome.com/releases/v5.7.2/css/fontawesome.csshttps://use.fontawesome.com/releases/v5.7.2/css/solid.csshttps://use.fontawesome.com/releases/v5.7.2/css/brands.csscmb2-field-type-font-awesome/css/faws/css/font-awesome.min.css?ver=cmb2-field-type-font-awesome/css/css/base/jquery.fonticonpicker.min.css?ver=cmb2-field-type-font-awesome/css/css/themes/grey-theme/jquery.fonticonpicker.grey.min.css?ver=cmb2-field-type-font-awesome/js/jquery.fonticonpicker.min.js?ver=cmb2-field-type-font-awesome/js/main.js?ver=HTML / DOM Fingerprints
iconselectfa