The Icon Block Security & Risk Analysis

wordpress.org/plugins/icon-block

Easily add SVG icons and graphics to the WordPress block editor.

30K active installs v2.0.0 PHP 7.4+ WP 6.5+ Updated Jan 18, 2026
blockiconicon-blocksvgsvg-block
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is The Icon Block Safe to Use in 2026?

Generally Safe

Score 100/100

The Icon Block has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "icon-block" plugin version 2.0.0 demonstrates an exceptionally strong security posture based on the provided static analysis and vulnerability history. The absence of any identified attack surface points, dangerous functions, direct SQL queries, unescaped output, file operations, external HTTP requests, nonce checks, or capability checks is a significant strength. This indicates that the developers have followed best practices for secure WordPress plugin development, minimizing potential entry points for malicious actors. Furthermore, the lack of any recorded vulnerabilities, including CVEs, suggests a history of responsible development and maintenance.

While the current analysis reveals no immediate risks, it's important to acknowledge that static analysis has limitations. The fact that zero taint flows were analyzed and zero unescaped outputs were found, while positive, could also indicate an incomplete analysis or a plugin with minimal complexity. However, based strictly on the data provided, the "icon-block" plugin v2.0.0 appears to be a very secure option. The comprehensive avoidance of common vulnerability patterns is a clear indicator of good development practices.

Vulnerabilities
None known

The Icon Block Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

The Icon Block Release Timeline

v2.0.0Current
v1.9.0
v1.8.0
v1.7.0
v1.6.0
v1.5.0
v1.4.0
v1.3.2
v1.3.1
v1.3.0
v1.2.0
v1.1.2
v1.1.1
v1.1.0
v1.0.0
v0.1.2
v0.1.1
v0.1.0
Code Analysis
Analyzed Mar 16, 2026

The Icon Block Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

The Icon Block Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioniniticon-block.php:30
filterblock_core_navigation_listable_blocksicon-block.php:46
Maintenance & Trust

The Icon Block Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 18, 2026
PHP min version7.4
Downloads298K

Community Trust

Rating100/100
Number of ratings29
Active installs30K
Developer Profile

The Icon Block Developer Profile

Nick Diego

5 plugins · 94K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
390 days
View full developer profile
Detection Fingerprints

How We Detect The Icon Block

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/icon-block/build/block.json/wp-content/plugins/icon-block/build/index.js/wp-content/plugins/icon-block/build/index.css
Script Paths
/wp-content/plugins/icon-block/build/index.js
Version Parameters
icon-block/build/index.css?ver=icon-block/build/index.js?ver=

HTML / DOM Fingerprints

CSS Classes
wp-block-outermost-icon-block
FAQ

Frequently Asked Questions about The Icon Block