Icon List Block – Add Icon-Based Lists with Custom Styles Security & Risk Analysis

wordpress.org/plugins/icon-list-block

Create a list with an icon with this block plugin.

4K active installs v1.2.8 PHP 7.1+ WP 6.7+ Updated Apr 16, 2026
blockbullet-listicon-listlist-iconmenu-icon
96
A · Safe
CVEs total3
Unpatched0
Last CVEFeb 15, 2026
Download
Safety Verdict

Is Icon List Block – Add Icon-Based Lists with Custom Styles Safe to Use in 2026?

Generally Safe

Score 96/100

Icon List Block – Add Icon-Based Lists with Custom Styles has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

3 known CVEsLast CVE: Feb 15, 2026Updated 1mo ago
Risk Assessment

The 'icon-list-block' plugin v1.2.7 exhibits a strong security posture based on static analysis. The code demonstrates good practices by utilizing prepared statements for all SQL queries, ensuring proper output escaping for all identified outputs, and implementing both nonce and capability checks on its entry points. The absence of file operations and external HTTP requests further reduces the attack surface. Taint analysis reveals no critical or high severity vulnerabilities, suggesting the developer is mindful of input sanitization. However, the plugin's vulnerability history, with two previously disclosed medium severity CVEs for SSRF and XSS, raises a notable concern. While there are currently no unpatched vulnerabilities, this history indicates a recurring pattern of exploitable weaknesses that could resurface. The presence of a bundled Freemius library, version 1.0, also introduces a potential risk if this library itself has known vulnerabilities, though no specific issues are highlighted in the provided data.

Key Concerns

  • Previous medium severity vulnerabilities
  • Bundled outdated library (Freemius v1.0)
Vulnerabilities
3 published

Icon List Block – Add Icon-Based Lists with Custom Styles Security Vulnerabilities

CVEs by Year

2 CVEs in 2025
2025
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2026-32359medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Icon List Block <= 1.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

Feb 15, 2026 Patched in 1.2.4 (60d)
CVE-2025-12376medium · 6.4Server-Side Request Forgery (SSRF)

Icon List Block – Add Icon-Based Lists with Custom Styles <= 1.2.1 - Authenticated (Subscriber+) Server-Side Request Forgery

Nov 18, 2025 Patched in 1.2.2 (1d)
CVE-2025-26937medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Icon List Block <= 1.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

Feb 23, 2025 Patched in 1.1.4 (9d)
Version History

Icon List Block – Add Icon-Based Lists with Custom Styles Release Timeline

Code Analysis
Analyzed Mar 16, 2026

Icon List Block – Add Icon-Based Lists with Custom Styles Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
7 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

100% escaped7 total outputs
Attack Surface

Icon List Block – Add Icon-Based Lists with Custom Styles Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_ilbPipeCheckerindex.php:68
noprivwp_ajax_ilbPipeCheckerindex.php:69

Shortcodes 1

[icon-list] index.php:59
WordPress Hooks 9
actionenqueue_block_assetsindex.php:48
actioninitindex.php:49
actionadmin_menuindex.php:51
actionadmin_enqueue_scriptsindex.php:52
actioninitindex.php:56
filtermanage_icon-list-block_posts_columnsindex.php:62
actionmanage_icon-list-block_posts_custom_columnindex.php:65
actionadmin_initindex.php:70
actionrest_api_initindex.php:71
Maintenance & Trust

Icon List Block – Add Icon-Based Lists with Custom Styles Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 16, 2026
PHP min version7.1
Downloads85K

Community Trust

Rating74/100
Number of ratings6
Active installs4K
Developer Profile

Icon List Block – Add Icon-Based Lists with Custom Styles Developer Profile

colorlibplugins

121 plugins · 740K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
130 days
View full developer profile
Detection Fingerprints

How We Detect Icon List Block – Add Icon-Based Lists with Custom Styles

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/icon-list-block/assets/css/font-awesome.min.css
Version Parameters
icon-list-block/assets/css/font-awesome.min.css?ver=6.4.2

HTML / DOM Fingerprints

CSS Classes
bPlAdminShortcodetooltip
Data Attributes
data-info
JS Globals
copyBPlAdminShortcode
REST Endpoints
/wp-json/wp/v2/icon-list-block
Shortcode Output
[icon-list id=
FAQ

Frequently Asked Questions about Icon List Block – Add Icon-Based Lists with Custom Styles