Icon Footnote Security & Risk Analysis

wordpress.org/plugins/icon-footnote

Gutemberg block that adds beautiful footnotes using material icons..

0 active installs v0.1.3 PHP 7.0+ WP 5.9+ Updated Sep 8, 2022
bibliographyblockfootnotesformatting
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Icon Footnote Safe to Use in 2026?

Generally Safe

Score 85/100

Icon Footnote has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "icon-footnote" plugin version 0.1.3 exhibits a very strong security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL queries without prepared statements, or unescaped output demonstrates adherence to core secure coding practices. Furthermore, the lack of file operations, external HTTP requests, and the explicit reporting of zero taint flows with unsanitized paths suggest a clean and well-developed codebase. The complete absence of recorded vulnerabilities in its history further bolsters this assessment, indicating a history of secure development or a lack of past exploitation.

However, the most significant concern arises from the complete lack of security checks such as nonce and capability checks across all entry points. While the static analysis reports zero entry points, this implies that any potential future introduction of AJAX handlers, REST API routes, or shortcodes would be inherently unprotected unless explicitly secured. The current lack of any detected attack surface is a strength, but it also means that the plugin's security mechanisms for handling user input or actions have not been tested or implemented. Therefore, while the current code is excellent, the absence of foundational security checks creates a potential future risk.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Icon Footnote Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Icon Footnote Release Timeline

v0.1.3Current
v0.1.2
Code Analysis
Analyzed Apr 16, 2026

Icon Footnote Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Icon Footnote Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actioniniticon-footnote.php:27
Maintenance & Trust

Icon Footnote Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedSep 8, 2022
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Icon Footnote Developer Profile

OpenDev.Consulting

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Icon Footnote

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/icon-footnote/build/index.js/wp-content/plugins/icon-footnote/build/style-index.css/wp-content/plugins/icon-footnote/build/index.asset.php
Script Paths
/wp-content/plugins/icon-footnote/build/index.js
Version Parameters
icon-footnote/build/index.js?ver=icon-footnote/build/style-index.css?ver=

HTML / DOM Fingerprints

CSS Classes
wp-block-create-block-icon-footnote
FAQ

Frequently Asked Questions about Icon Footnote