JVM Rich Text Icons Security & Risk Analysis
wordpress.org/plugins/jvm-rich-text-iconsInsert icons anywhere in your content — inline in text, headings, buttons, or as a standalone block.
Is JVM Rich Text Icons Safe to Use in 2026?
Generally Safe
Score 98/100JVM Rich Text Icons has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The jvm-rich-text-icons v1.6.6 plugin exhibits a mixed security posture. While it demonstrates good practices by utilizing prepared statements for a majority of its SQL queries, performing a reasonable number of capability checks, and having no critical or high severity taint flows, there are significant areas of concern. The presence of two AJAX handlers without authentication checks represents a notable attack vector that could be exploited by unauthenticated users. Furthermore, the plugin's history of high-severity vulnerabilities, specifically Path Traversal and Unrestricted File Upload, is a strong indicator of past code quality issues that require careful monitoring. Although there are currently no unpatched CVEs, the recurrence of these vulnerability types suggests a potential for future exploitable flaws if coding practices do not consistently prioritize secure development. The plugin's moderate output escaping percentage also warrants attention, as it could lead to cross-site scripting vulnerabilities if user-supplied data is not properly sanitized before display.
Key Concerns
- AJAX handlers without authentication checks
- Moderate output escaping percentage
- History of high severity vulnerabilities (2 CVEs)
JVM Rich Text Icons Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
JVM rich text icons <= 1.2.6 - Directory Traversal to Authenticated(Subscriber+) Arbitrary File Deletion
JVM rich text icons <= 1.2.3 - Authenticated(Subscriber+) Arbitrary File Upload
JVM Rich Text Icons Release Timeline
JVM Rich Text Icons Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
JVM Rich Text Icons Attack Surface
AJAX Handlers 4
WordPress Hooks 18
Maintenance & Trust
JVM Rich Text Icons Maintenance & Trust
Maintenance Signals
Community Trust
JVM Rich Text Icons Alternatives
Omni Icon – Modern SVG icon library for WordPress
omni-icon
A modern SVG icon library for WordPress with support for custom uploads and 200,000+ Iconify icons across block editor, page builders, and themes.
The Icon Block
icon-block
Easily add SVG icons and graphics to the WordPress block editor.
Spectre Icons
spectre-icons
Curated SVG icon libraries for Elementor with fast manifests, inline rendering, and color controls.
RIACO Icon Block
riaco-icon-block
RIACO Icon Block add SVG icons as WordPress block with full control over icon selection and style.
SVG Heroicons Block
svg-heroicons-block
A Gutenberg block for Heroicons, an open source set of SVG icons at https://heroicons.com. ⚠️ Note: This is not an offical plugin from Tailwind Labs …
JVM Rich Text Icons Developer Profile
5 plugins · 4K total installs
How We Detect JVM Rich Text Icons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/jvm-rich-text-icons/dist/acf.js/wp-content/plugins/jvm-rich-text-icons/css/frontend.css/wp-content/plugins/jvm-rich-text-icons/css/editor.css/wp-content/plugins/jvm-rich-text-icons/dist/acf.jsjvm-rich-text-icons/css/frontend.css?ver=jvm-rich-text-icons/css/editor.css?ver=HTML / DOM Fingerprints
jvm-rich-text-iconjvm-rich-text-icons-select2<!-- WordPress core is in control of block settings. We override this by setting inline CSS. --><!-- Filter hook for inline SVG output --><!-- Review notice timing --><!-- Enable ACF fields -->data-acf-field-idwindow.acf/wp-json/acf/v1/fields/jvm_rich_text_icons<i class="jvm-rich-text-icon<span class="jvm-rich-text-icons-select2">