
Font Awesome Box Shortcode Security & Risk Analysis
wordpress.org/plugins/fa-box-shortcodeThe Font Awesome box shortcode plugin adds slim information box style shortcodes to your WordPress site which support displaying any of the Font Aweso …
Is Font Awesome Box Shortcode Safe to Use in 2026?
Generally Safe
Score 85/100Font Awesome Box Shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The fa-box-shortcode plugin v1.0.1 exhibits a generally good security posture based on the static analysis. The absence of dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, and the use of prepared statements for all SQL queries are strong indicators of secure coding practices. Furthermore, the plugin demonstrates proper use of capability checks (2 in total) to restrict access to its functionalities.
However, a significant concern arises from the lack of nonce checks. While the plugin has a limited attack surface consisting of a single shortcode with no observed taint flows or unpatched vulnerabilities, the absence of nonces on potential entry points leaves it vulnerable to Cross-Site Request Forgery (CSRF) attacks. Although there are no currently known CVEs and the vulnerability history is clean, this oversight is a common and potentially exploitable weakness that could allow an attacker to trick authenticated users into performing unintended actions. The bundled TinyMCE library, while common, should also be kept updated to prevent potential vulnerabilities within it.
In conclusion, fa-box-shortcode v1.0.1 is well-coded in many respects, particularly concerning data handling and access control. The major weakness is the missing nonce checks, which is a critical oversight for any plugin with user-facing interactions. The clean vulnerability history is positive but does not negate the inherent risk posed by the CSRF vulnerability. Addressing the nonce check deficiency would significantly improve the plugin's overall security.
Key Concerns
- Missing nonce checks
- Bundled TinyMCE library
Font Awesome Box Shortcode Security Vulnerabilities
Font Awesome Box Shortcode Release Timeline
Font Awesome Box Shortcode Code Analysis
Bundled Libraries
Output Escaping
Font Awesome Box Shortcode Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Font Awesome Box Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
Font Awesome Box Shortcode Alternatives
Space Boxes
space-boxes
Generate unlimited boxes with multiple layouts and optional lightbox, solely from a Wordpress media gallery.
Column Shortcodes
column-shortcodes
Adds shortcodes to easily create columns in your posts or pages.
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Futurio Extra
futurio-extra
Futurio Extra add extra features to Futurio theme like widgets, WooCommerce options, Elementor widgets, one click demo import and much more.
ND Shortcodes
nd-shortcodes
The plugin adds some useful components to your page builder ( Elementor or WP Bakery Page Builder ). All components are full responsive and retina rea …
Font Awesome Box Shortcode Developer Profile
3 plugins · 7K total installs
How We Detect Font Awesome Box Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fa-box-shortcode/assets/css/fa-box-shortcode.css/wp-content/plugins/fa-box-shortcode/assets/js/fa-box-shortcode.jsfa-box-shortcode/assets/css/fa-box-shortcode.css?ver=fa-box-shortcode/assets/js/fa-box-shortcode.js?ver=HTML / DOM Fingerprints
fabs-shortcode-boxfabs-urlfabs-boxfabs-icondata-plugin-name="Font Awesome Box Shortcode"data-plugin-uri="https://wordpress.org/plugins/fa-box-shortcode/"<div class="fabs-shortcode-box"><a href="" class="fabs-url" target="_blank"><div class="fabs-box