Coothemes Icons Security & Risk Analysis

wordpress.org/plugins/coothemes-icons

Easily and quickly use 2,000+ beautifully designed SVG font icons on your website

10 active installs v1.0.2 PHP 5.2.4+ WP 4.0.+ Updated Jul 27, 2018
font-awesomefont-iconiconiconssvg
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Coothemes Icons Safe to Use in 2026?

Generally Safe

Score 85/100

Coothemes Icons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The coothemes-icons plugin version 1.0.2 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and the high percentage of properly escaped output are positive indicators. Furthermore, the plugin has no recorded vulnerabilities (CVEs) and no identified taint flows, suggesting a clean codebase with no readily apparent critical security flaws. The limited attack surface, consisting of a single shortcode with no explicitly stated authentication checks, is also a positive. The plugin also avoids external HTTP requests and file operations, further reducing potential exposure. However, the lack of any recorded nonce checks or capability checks, despite having an entry point via a shortcode, could represent a potential area for concern if the shortcode's functionality is sensitive or can be leveraged in unexpected ways. While no critical issues are immediately evident, the absence of these security mechanisms warrants careful consideration in a real-world deployment. Overall, the plugin appears to be built with good security practices in mind, but the lack of explicit authorization checks on its sole entry point is a minor weakness.

Key Concerns

  • Shortcode without explicit capability checks
  • Shortcode without nonce checks
Vulnerabilities
None known

Coothemes Icons Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Coothemes Icons Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
16 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

84% escaped19 total outputs
Attack Surface

Coothemes Icons Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[ctic-icons] public\shortcodes.php:115
WordPress Hooks 6
actionadmin_enqueue_scriptsadmin\class-admin.php:51
actionadmin_enqueue_scriptsadmin\class-admin.php:52
actionadmin_menuadmin\icons-page.php:35
actionadmin_initadmin\icons-page.php:72
actionwp_enqueue_scriptsincludes\class-coothemes-icons.php:69
actionwp_enqueue_scriptsincludes\class-coothemes-icons.php:70
Maintenance & Trust

Coothemes Icons Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJul 27, 2018
PHP min version5.2.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Coothemes Icons Developer Profile

coothemes

3 plugins · 60 total installs

79
trust score
Avg Security Score
78/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Coothemes Icons

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/coothemes-icons/css/cts-icons/coothemes-icons.css/wp-content/plugins/coothemes-icons/css/admin-style.css/wp-content/plugins/coothemes-icons/js/admin-scripts.js
Script Paths
/wp-content/plugins/coothemes-icons/js/admin-scripts.js
Version Parameters
coothemes-icons/css/cts-icons/coothemes-icons.css?ver=coothemes-icons/js/admin-scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
ctp-gray
HTML Comments
Coothemes Icons - CTIC ctic
Data Attributes
data-ctc-icondata-ctc-icon-titledata-ctc-icon-id
JS Globals
localized_data
Shortcode Output
[coothemes_icons][coothemes_icon]
FAQ

Frequently Asked Questions about Coothemes Icons