Custom Icons for Elementor Security & Risk Analysis

wordpress.org/plugins/custom-icons-for-elementor

Add custom icon fonts to the built in Elementor icon controls

10K active installs v0.3.4 PHP 7.4+ WP 5.4+ Updated Oct 28, 2024
elementorfontelloicon-fontsicons
90
A · Safe
CVEs total1
Unpatched0
Last CVEOct 21, 2024
Download
Safety Verdict

Is Custom Icons for Elementor Safe to Use in 2026?

Generally Safe

Score 90/100

Custom Icons for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Oct 21, 2024Updated 1yr ago
Risk Assessment

The plugin "custom-icons-for-elementor" v0.3.4 exhibits a generally positive security posture based on the static analysis, with no identified dangerous functions, all SQL queries using prepared statements, and a good proportion of output escaping. The absence of detectable taint flows and the presence of nonce and capability checks are also encouraging signs. However, the presence of 8 file operations and 2 external HTTP requests warrants careful review to ensure these operations do not introduce vulnerabilities, especially considering a past high-severity vulnerability related to unrestricted file uploads.

The vulnerability history is a significant concern. While there are no currently unpatched CVEs, the plugin has a recorded history of one high-severity vulnerability, specifically "Unrestricted Upload of File with Dangerous Type," which was patched relatively recently. This pattern suggests a potential for similar vulnerabilities to emerge if input sanitization and file handling are not rigorously implemented and audited. The overall risk is moderate, with strengths in core secure coding practices but a notable weakness in its past vulnerability profile regarding file handling.

Key Concerns

  • Past high-severity vulnerability (unrestricted upload)
  • File operations present (8 total)
  • External HTTP requests present (2 total)
  • Output escaping not fully proper (70%)
Vulnerabilities
1

Custom Icons for Elementor Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2024-49676high · 7.2Unrestricted Upload of File with Dangerous Type

Custom Icons for Elementor <= 0.3.3 - Authenticated (Admin+) Arbitrary File Upload

Oct 21, 2024 Patched in 0.3.4 (10d)
Code Analysis
Analyzed Mar 16, 2026

Custom Icons for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
31 escaped
Nonce Checks
2
Capability Checks
4
File Operations
8
External Requests
2
Bundled Libraries
0

Output Escaping

70% escaped44 total outputs
Attack Surface

Custom Icons for Elementor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_menuelementor-custom-icons.php:105
actionadmin_initelementor-custom-icons.php:107
actionadmin_enqueue_scriptselementor-custom-icons.php:110
actionadmin_enqueue_scriptselementor-custom-icons.php:111
actionwp_enqueue_scriptselementor-custom-icons.php:114
actionwp_enqueue_scripts_cleanelementor-custom-icons.php:115
actionwp_print_footer_scriptselementor-custom-icons.php:118
actionelementor/controls/controls_registeredelementor-custom-icons.php:121
filterelementor/icons_manager/additional_tabselementor-custom-icons.php:122
actionplugins_loadedelementor-custom-icons.php:148
Maintenance & Trust

Custom Icons for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedOct 28, 2024
PHP min version7.4
Downloads248K

Community Trust

Rating90/100
Number of ratings33
Active installs10K
Developer Profile

Custom Icons for Elementor Developer Profile

Michael Bourne

2 plugins · 11K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
10 days
View full developer profile
Detection Fingerprints

How We Detect Custom Icons for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/custom-icons-for-elementor/assets/css/elementor-custom-icons.css/wp-content/plugins/custom-icons-for-elementor/assets/js/elementor-custom-icons.js
Script Paths
/wp-content/plugins/custom-icons-for-elementor/assets/js/elementor-custom-icons.js
Version Parameters
custom-icons-for-elementor/assets/css/elementor-custom-icons.css?ver=custom-icons-for-elementor/assets/js/elementor-custom-icons.js?ver=

HTML / DOM Fingerprints

CSS Classes
eci-add-icon-font
Data Attributes
data-eci-upload-nonce
JS Globals
eci_scriptECIcons_VERSIONECIcons_URI
FAQ

Frequently Asked Questions about Custom Icons for Elementor