Icon List Block – Add Icon-Based Lists with Custom Styles Security & Risk Analysis

wordpress.org/plugins/icon-list-block

Create a list with an icon with this block plugin.

4K active installs v1.2.7 PHP 7.1+ WP 6.5+ Updated Mar 14, 2026
blockbullet-listicon-listlist-iconmenu-icon
98
A · Safe
CVEs total2
Unpatched0
Last CVENov 18, 2025
Download
Safety Verdict

Is Icon List Block – Add Icon-Based Lists with Custom Styles Safe to Use in 2026?

Generally Safe

Score 98/100

Icon List Block – Add Icon-Based Lists with Custom Styles has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Nov 18, 2025Updated 20d ago
Risk Assessment

The 'icon-list-block' plugin v1.2.7 exhibits a strong security posture based on static analysis. The code demonstrates good practices by utilizing prepared statements for all SQL queries, ensuring proper output escaping for all identified outputs, and implementing both nonce and capability checks on its entry points. The absence of file operations and external HTTP requests further reduces the attack surface. Taint analysis reveals no critical or high severity vulnerabilities, suggesting the developer is mindful of input sanitization. However, the plugin's vulnerability history, with two previously disclosed medium severity CVEs for SSRF and XSS, raises a notable concern. While there are currently no unpatched vulnerabilities, this history indicates a recurring pattern of exploitable weaknesses that could resurface. The presence of a bundled Freemius library, version 1.0, also introduces a potential risk if this library itself has known vulnerabilities, though no specific issues are highlighted in the provided data.

Key Concerns

  • Previous medium severity vulnerabilities
  • Bundled outdated library (Freemius v1.0)
Vulnerabilities
2

Icon List Block – Add Icon-Based Lists with Custom Styles Security Vulnerabilities

CVEs by Year

2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-12376medium · 6.4Server-Side Request Forgery (SSRF)

Icon List Block – Add Icon-Based Lists with Custom Styles <= 1.2.1 - Authenticated (Subscriber+) Server-Side Request Forgery

Nov 18, 2025 Patched in 1.2.2 (1d)
CVE-2025-26937medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Icon List Block <= 1.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

Feb 23, 2025 Patched in 1.1.4 (9d)
Code Analysis
Analyzed Mar 16, 2026

Icon List Block – Add Icon-Based Lists with Custom Styles Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
7 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

100% escaped7 total outputs
Attack Surface

Icon List Block – Add Icon-Based Lists with Custom Styles Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_ilbPipeCheckerindex.php:68
noprivwp_ajax_ilbPipeCheckerindex.php:69

Shortcodes 1

[icon-list] index.php:59
WordPress Hooks 9
actionenqueue_block_assetsindex.php:48
actioninitindex.php:49
actionadmin_menuindex.php:51
actionadmin_enqueue_scriptsindex.php:52
actioninitindex.php:56
filtermanage_icon-list-block_posts_columnsindex.php:62
actionmanage_icon-list-block_posts_custom_columnindex.php:65
actionadmin_initindex.php:70
actionrest_api_initindex.php:71
Maintenance & Trust

Icon List Block – Add Icon-Based Lists with Custom Styles Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 14, 2026
PHP min version7.1
Downloads81K

Community Trust

Rating74/100
Number of ratings6
Active installs4K
Developer Profile

Icon List Block – Add Icon-Based Lists with Custom Styles Developer Profile

colorlibplugins

120 plugins · 738K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
140 days
View full developer profile
Detection Fingerprints

How We Detect Icon List Block – Add Icon-Based Lists with Custom Styles

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/icon-list-block/assets/css/font-awesome.min.css
Version Parameters
icon-list-block/assets/css/font-awesome.min.css?ver=6.4.2

HTML / DOM Fingerprints

CSS Classes
bPlAdminShortcodetooltip
Data Attributes
data-info
JS Globals
copyBPlAdminShortcode
REST Endpoints
/wp-json/wp/v2/icon-list-block
Shortcode Output
[icon-list id=
FAQ

Frequently Asked Questions about Icon List Block – Add Icon-Based Lists with Custom Styles