Icons Font Loader – Load Web Fonts and Icon Libraries Security & Risk Analysis

wordpress.org/plugins/icons-font-loader

Load essential Flaticon webfonts into your WordPress site. Use icons anywhere on your site with simple integration, ensuring fast performance.

2K active installs v1.1.7 PHP 7.1+ WP 4.7+ Updated Feb 4, 2026
flaticonfonticon-fontsiconswebfonts
98
A · Safe
CVEs total3
Unpatched0
Last CVEJan 31, 2024
Safety Verdict

Is Icons Font Loader – Load Web Fonts and Icon Libraries Safe to Use in 2026?

Generally Safe

Score 98/100

Icons Font Loader – Load Web Fonts and Icon Libraries has a strong security track record. Known vulnerabilities have been patched promptly.

3 known CVEsLast CVE: Jan 31, 2024Updated 1mo ago
Risk Assessment

The "icons-font-loader" plugin version 1.1.7 presents a mixed security posture. While the static analysis indicates a relatively small attack surface with no direct vulnerabilities found in the analyzed code, the historical vulnerability data raises significant concerns. The presence of 3 past CVEs, including 2 high and 1 medium severity, with common patterns of SQL injection and unrestricted file uploads, suggests recurring weaknesses in the plugin's development. The fact that the latest vulnerability was as recent as January 2024 and is currently unpatched is a major red flag, indicating that these past issues may not have been fully remediated or that new ones have emerged.

Although the current static analysis shows no critical or high taint flows, and a good percentage of SQL queries are prepared and outputs are escaped, the historical context cannot be ignored. The absence of capability checks on its single AJAX handler is a weakness, as it means any authenticated user could potentially trigger this functionality. The plugin's history of critical vulnerability types points to a need for rigorous security auditing and a more robust development lifecycle to prevent these types of issues from recurring.

In conclusion, while the immediate static analysis doesn't reveal active exploitable vulnerabilities in this specific version, the plugin's past and the unpatched nature of its latest known vulnerability make it a moderate to high-risk component. The potential for SQL injection and file upload vulnerabilities to re-emerge, coupled with the lack of capability checks on its entry points, necessitates caution. Users should strongly consider updating to a version that has addressed all known vulnerabilities, and developers should focus on more secure coding practices and thorough security testing.

Key Concerns

  • Unpatched vulnerability history (3 total, 2 high, 1 medium)
  • Lack of capability checks on AJAX handler
  • SQL queries: 50% not using prepared statements
  • File operations detected
Vulnerabilities
3

Icons Font Loader – Load Web Fonts and Icon Libraries Security Vulnerabilities

CVEs by Year

2 CVEs in 2023
2023
1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

High
2
Medium
1

3 total CVEs

CVE-2024-24714medium · 6.6Unrestricted Upload of File with Dangerous Type

Icons Font Loader <= 1.1.4 - Authenticated(Administrator+) Arbitrary File Upload

Jan 31, 2024 Patched in 1.1.5 (3d)
CVE-2023-5860high · 7.2Unrestricted Upload of File with Dangerous Type

Icons Font Loader <= 1.1.2 - Authenticated (Administrator+) Arbitrary File Upload

Nov 1, 2023 Patched in 1.1.3 (83d)
CVE-2023-46084high · 8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Icons Font Loader <= 1.1.2 - Authenticated (Subscriber+) SQL Injection

Oct 16, 2023 Patched in 1.1.3 (99d)
Code Analysis
Analyzed Mar 16, 2026

Icons Font Loader – Load Web Fonts and Icon Libraries Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
2 prepared
Unescaped Output
3
22 escaped
Nonce Checks
2
Capability Checks
0
File Operations
5
External Requests
0
Bundled Libraries
0

SQL Query Safety

50% prepared4 total queries

Output Escaping

88% escaped25 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
bifl_ajax_call (init.php:65)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Icons Font Loader – Load Web Fonts and Icon Libraries Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_bifl_ajax_callinit.php:33
WordPress Hooks 7
actioninitinit.php:30
actionplugins_loadedinit.php:31
actionwp_enqueue_scriptsinit.php:32
actionwp_headinit.php:34
actionadmin_initinit.php:38
actionadmin_menuinit.php:39
actionadmin_enqueue_scriptsinit.php:40
Maintenance & Trust

Icons Font Loader – Load Web Fonts and Icon Libraries Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 4, 2026
PHP min version7.1
Downloads22K

Community Trust

Rating100/100
Number of ratings1
Active installs2K
Developer Profile

Icons Font Loader – Load Web Fonts and Icon Libraries Developer Profile

colorlibplugins

120 plugins · 738K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
140 days
View full developer profile
Detection Fingerprints

How We Detect Icons Font Loader – Load Web Fonts and Icon Libraries

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/icons-font-loader/assets/js/script.js/wp-content/plugins/icons-font-loader/assets/css/style.css
Script Paths
/wp-content/plugins/icons-font-loader/assets/js/script.js
Version Parameters
icons-font-loader/assets/js/script.js?ver=icons-font-loader/assets/css/style.css?ver=

HTML / DOM Fingerprints

Data Attributes
bifl_form
JS Globals
bifl
FAQ

Frequently Asked Questions about Icons Font Loader – Load Web Fonts and Icon Libraries