Google Plus Favicon Security & Risk Analysis

wordpress.org/plugins/google-plus-favicon

Simply add a Google+ account ID to generate a G+ favicon for your blog and admin logo included Apple touch icon.

10 active installs v3.0 PHP + WP 2.5+ Updated Aug 29, 2011
bookmarkggoogleiconplus
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Google Plus Favicon Safe to Use in 2026?

Generally Safe

Score 85/100

Google Plus Favicon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The 'google-plus-favicon' plugin v3.0 exhibits a seemingly strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the analysis indicates that all SQL queries are performed using prepared statements, which is a crucial best practice for preventing SQL injection vulnerabilities. The lack of any recorded vulnerabilities in its history also suggests a history of stable and secure development.

However, there are some areas of concern. The low percentage of properly escaped output (10%) indicates a potential for Cross-Site Scripting (XSS) vulnerabilities. If user-supplied data is not properly sanitized before being displayed, it could be exploited by attackers. Additionally, the complete absence of nonce checks and capability checks on any potential entry points (though none were identified in the attack surface analysis) is a weakness. While the attack surface is currently zero, if any new entry points are introduced in future updates without these essential security measures, the plugin would be vulnerable.

In conclusion, while the plugin benefits from a very small attack surface and secure SQL handling, the significant lack of output escaping and the absence of any authentication or authorization checks on potential entry points represent notable security weaknesses. The clean vulnerability history is positive, but the identified code quality issues, particularly around output sanitization, warrant attention.

Key Concerns

  • Low output escaping percentage
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Google Plus Favicon Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Google Plus Favicon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
5
External Requests
1
Bundled Libraries
0

Output Escaping

10% escaped10 total outputs
Attack Surface

Google Plus Favicon Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_initgoogle-plus-favicon.php:28
actionwp_headgoogle-plus-favicon.php:200
actionadmin_headgoogle-plus-favicon.php:201
actionlogin_headgoogle-plus-favicon.php:202
actionadmin_headgoogle-plus-favicon.php:203
actionrss_headgoogle-plus-favicon.php:204
actionrss2_headgoogle-plus-favicon.php:205
filterplugin_row_metagoogle-plus-favicon.php:207
Maintenance & Trust

Google Plus Favicon Maintenance & Trust

Maintenance Signals

WordPress version tested3.2.1
Last updatedAug 29, 2011
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Google Plus Favicon Developer Profile

Patrick Chia

8 plugins · 170 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Google Plus Favicon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

HTML Comments
<!-- G+ Favicon by Patrick http://patrick.bloggles.info/ --><!-- Error: Please make sure the Google account is <a href="http://plus.google.com/">public</a>. --><!-- Error: Google Plus did not respond. Please wait a few minutes and refresh this page. -->
REST Endpoints
/buzz/v1/people/
FAQ

Frequently Asked Questions about Google Plus Favicon