
Ed's Font Awesome Security & Risk Analysis
wordpress.org/plugins/eds-font-awesomeEd's Font Awesome Plugin is the ultimate Font Awesome Icon Shortcode plugin. Place over 2,000 font awesome icons anywhere on your WordPress site …
Is Ed's Font Awesome Safe to Use in 2026?
Mostly Safe
Score 78/100Ed's Font Awesome is generally safe to use. 1 past CVE were resolved.
The "eds-font-awesome" v3.0 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals strong adherence to secure coding practices, with 100% of SQL queries using prepared statements and 100% of output properly escaped. There are no identified dangerous functions, file operations, external HTTP requests, or bundled libraries, which are all good indicators. However, a significant concern arises from the absence of nonce checks and capability checks across all identified entry points (10 shortcodes). While there are no unprotected AJAX handlers or REST API routes, the lack of these fundamental security mechanisms on shortcodes leaves them potentially vulnerable to unauthorized execution or manipulation. The vulnerability history is also a major red flag, with one unpatched medium severity CVE classified as Cross-Site Scripting (XSS). This, coupled with the absence of specific security checks on entry points, suggests a potential for attackers to exploit this plugin to inject malicious scripts.
Key Concerns
- Unpatched medium severity CVE (XSS)
- Missing nonce checks on all entry points
- Missing capability checks on all entry points
Ed's Font Awesome Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Ed's Font Awesome <= 2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
Ed's Font Awesome Release Timeline
Ed's Font Awesome Code Analysis
Output Escaping
Ed's Font Awesome Attack Surface
Shortcodes 10
WordPress Hooks 4
Maintenance & Trust
Ed's Font Awesome Maintenance & Trust
Maintenance Signals
Community Trust
Ed's Font Awesome Alternatives
Creative FA and BS Icons Shortcode
creative-fa-and-bs-icons-shortcode
This plugin Allows you to add Font-Awesome and Bootstrap Icons Easily using shortcode. Just install and activate this plugin and use shortcode for usi …
Cf7 Icons and Labels
cf7-icons-and-labels
This plugin can be used to add font awesome icons and labels to the Contact Form 7.
SS Font Awesome Icon
ss-font-awesome-icon
Easiest way to integrate Font Awesome Icon in any post or widget.
Ultimate Icon Shortcodes – LITE
ultimate-icon-shortcodes
This plugin will add a small button to your post / page editor, clicking on that will bring up our visual icon selector. Choose the icon you want and …
Popular Brand Icons – Simple Icons
simple-icons
An easy to use lightweight SVG icons plugin with over 1500+ brand icons. Use these icons in your menus, widgets, posts, or pages.
Ed's Font Awesome Developer Profile
2 plugins · 0 total installs
How We Detect Ed's Font Awesome
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/eds-font-awesome/css/font-awesome.min.css/wp-content/plugins/eds-font-awesome/js/fontawesome-all.min.js/wp-content/plugins/eds-font-awesome/js/fontawesome-all.min.jseds-font-awesome/css/font-awesome.min.css?ver=eds-font-awesome/js/fontawesome-all.min.js?ver=HTML / DOM Fingerprints
eds_font_awesomedata-fa-transformdata-fa-mask<i class="<div class="fa-fa-layers fa-fw