<i> Toolbar Security & Risk Analysis

wordpress.org/plugins/i-toolbar

<i> Toolbar is an easy to use Icon picker that integrates in the rich-text block toolbar. Powered by Bootstrap Icons (MIT).

80 active installs v1.2.2 PHP 7.2+ WP 5.6+ Updated Feb 12, 2026
bootstrapeditorgutenbergiconicons
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is <i> Toolbar Safe to Use in 2026?

Generally Safe

Score 100/100

<i> Toolbar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the i-toolbar plugin v1.2.2 exhibits a very strong security posture. The static analysis reveals no identified entry points such as AJAX handlers, REST API routes, or shortcodes, which significantly reduces the potential attack surface. Furthermore, the code signals indicate no dangerous functions are used, all SQL queries are properly prepared, and output is consistently escaped, which are excellent security practices. The lack of any recorded vulnerabilities, past or present, is also a positive indicator of the plugin's security development and maintenance. The plugin also demonstrates adherence to security by not making external HTTP requests and not relying on bundled libraries, which can sometimes introduce vulnerabilities. The only minor point to note is the absence of explicit nonce and capability checks, which could be seen as a missed opportunity for defense-in-depth in the rare event that an unexpected entry point were discovered, though with the current findings, this is a very low risk. Overall, the plugin appears to be securely developed and maintained, with a negligible risk profile.

Key Concerns

  • No nonce checks
  • No capability checks
Vulnerabilities
None known

<i> Toolbar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

<i> Toolbar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

<i> Toolbar Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionenqueue_block_assetsi-toolbar.php:72
Maintenance & Trust

<i> Toolbar Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 12, 2026
PHP min version7.2
Downloads9K

Community Trust

Rating0/100
Number of ratings0
Active installs80
Developer Profile

<i> Toolbar Developer Profile

them.es

4 plugins · 2K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect <i> Toolbar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/i-toolbar/assets/admin/css/style-editor.css/wp-content/plugins/i-toolbar/assets/bootstrap-icons/font/bootstrap-icons.css/wp-content/plugins/i-toolbar/blocks/build/index.js
Script Paths
/wp-content/plugins/i-toolbar/blocks/build/index.js
Version Parameters
i-toolbar/blocks/build/index.js?ver=i-toolbar/assets/admin/css/style-editor.css?ver=i-toolbar/assets/bootstrap-icons/font/bootstrap-icons.css?ver=

HTML / DOM Fingerprints

JS Globals
globalBootstrapIconToolbarData
FAQ

Frequently Asked Questions about <i> Toolbar