Favicon by RealFaviconGenerator Security & Risk Analysis
wordpress.org/plugins/favicon-by-realfavicongeneratorCreate and install your favicon for all platforms: PC/Mac, iPhone/iPad, Android devices, Windows 8 tablets...
Is Favicon by RealFaviconGenerator Safe to Use in 2026?
Generally Safe
Score 96/100Favicon by RealFaviconGenerator has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin 'favicon-by-realfavicongenerator' v1.3.46 exhibits a mixed security posture. While the static analysis shows a remarkably small attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events, and the taint analysis found no critical or high-severity issues, there are significant concerns related to its past vulnerability history and code signals. The plugin has a history of 4 known CVEs, including one high-severity and three medium-severity vulnerabilities, primarily related to Cross-Site Request Forgery and Cross-Site Scripting. The most recent vulnerability was patched in April 2024, suggesting active patching, but the recurring nature of these vulnerability types is a concern. Furthermore, the presence of SQL queries not using prepared statements and a lack of capability checks on any entry points (though the entry point count is zero) are weaknesses that, if an attack vector were to emerge, could be exploited. The high percentage of properly escaped output is a strength, but it does not entirely mitigate the risks posed by the historical vulnerabilities and the raw SQL query.
Key Concerns
- 1 High severity CVE (unpatched)
- 3 Medium severity CVEs (unpatched)
- SQL queries without prepared statements
- 0 Capability checks on entry points
- Flows with unsanitized paths
Favicon by RealFaviconGenerator Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Favicon <= 1.3.29 - Cross-Site Request Forgery to Notice Dismissal
Favicon by RealFaviconGenerator <= 1.3.22 - Reflected Cross-Site Scripting
Favicon by RealFaviconGenerator <= 1.3.21 - Reflected Cross-Site Scripting
Favicon by RealFaviconGenerator <= 1.2.12 - Reflected Cross-Site Scripting
Favicon by RealFaviconGenerator Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Favicon by RealFaviconGenerator Attack Surface
WordPress Hooks 12
Maintenance & Trust
Favicon by RealFaviconGenerator Maintenance & Trust
Maintenance Signals
Community Trust
Favicon by RealFaviconGenerator Alternatives
Multicons
multicons
Multicons is a multi-favicon code generator which automatically inserts the necessary meta tags for favicons.
wp-logo-login | تغییر لوگو ورود و سربرگ
change-logo-login
With the help of this plugin, you can change the logo of the WordPress admin section.
All In One Favicon
all-in-one-favicon
Easily add a Favicon to your site and the WordPress admin pages. Complete with upload functionality. Supports all three Favicon types (ico,png,gif).
Favicon Rotator
favicon-rotator
Easily set site favicon and even rotate through multiple icons
WP Favicon Remover
wp-favicon-remover
This plugin adds the functionality to remove the WordPress default favicon since WordPress 5.4.
Favicon by RealFaviconGenerator Developer Profile
1 plugin · 200K total installs
How We Detect Favicon by RealFaviconGenerator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/favicon-by-realfavicongenerator/public/css/site.css/wp-content/plugins/favicon-by-realfavicongenerator/public/js/site.js/wp-content/plugins/favicon-by-realfavicongenerator/admin/assets/css/admin.cssFavicon by RealFaviconGeneratorfavicon-by-realfavicongenerator/public/css/site.css?ver=favicon-by-realfavicongenerator/public/js/site.js?ver=favicon-by-realfavicongenerator/admin/assets/css/admin.css?ver=HTML / DOM Fingerprints
favicon_settings_pagefbrfg-settings-wrapfavicon_appearance_pagefbrfg-appearance-wrap<!-- Favicon by RealFaviconGenerator --><!-- Favicon settings --><!-- Favicon Appearance settings -->data-plugin-slug="favicon-by-realfavicongenerator"data-realfavicongenerator-ajax-urlwindow.FaviconByRealFaviconGeneratorAdmin/wp-json/favicon-by-realfavicongenerator/v1/settings