JVM Rich Text Icons Security & Risk Analysis
wordpress.org/plugins/jvm-rich-text-iconsInsert icons anywhere in your content — inline in text, headings, buttons, or as a standalone block.
Is JVM Rich Text Icons Safe to Use in 2026?
Generally Safe
Score 98/100JVM Rich Text Icons has a strong security track record. Known vulnerabilities have been patched promptly.
The jvm-rich-text-icons v1.6.6 plugin exhibits a mixed security posture. While it demonstrates good practices by utilizing prepared statements for a majority of its SQL queries, performing a reasonable number of capability checks, and having no critical or high severity taint flows, there are significant areas of concern. The presence of two AJAX handlers without authentication checks represents a notable attack vector that could be exploited by unauthenticated users. Furthermore, the plugin's history of high-severity vulnerabilities, specifically Path Traversal and Unrestricted File Upload, is a strong indicator of past code quality issues that require careful monitoring. Although there are currently no unpatched CVEs, the recurrence of these vulnerability types suggests a potential for future exploitable flaws if coding practices do not consistently prioritize secure development. The plugin's moderate output escaping percentage also warrants attention, as it could lead to cross-site scripting vulnerabilities if user-supplied data is not properly sanitized before display.
Key Concerns
- AJAX handlers without authentication checks
- Moderate output escaping percentage
- History of high severity vulnerabilities (2 CVEs)
JVM Rich Text Icons Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
JVM rich text icons <= 1.2.6 - Directory Traversal to Authenticated(Subscriber+) Arbitrary File Deletion
JVM rich text icons <= 1.2.3 - Authenticated(Subscriber+) Arbitrary File Upload
JVM Rich Text Icons Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
JVM Rich Text Icons Attack Surface
AJAX Handlers 4
WordPress Hooks 18
Maintenance & Trust
JVM Rich Text Icons Maintenance & Trust
Maintenance Signals
Community Trust
JVM Rich Text Icons Alternatives
Omni Icon – Modern SVG icon library for WordPress
omni-icon
A modern SVG icon library for WordPress with support for custom uploads and 200,000+ Iconify icons across block editor, page builders, and themes.
The Icon Block
icon-block
Easily add SVG icons and graphics to the WordPress block editor.
Spectre Icons
spectre-icons
Curated SVG icon libraries for Elementor with fast manifests, inline rendering, and color controls.
SVG Heroicons Block
svg-heroicons-block
A Gutenberg block for Heroicons, an open source set of SVG icons at https://heroicons.com. ⚠️ Note: This is not an offical plugin from Tailwind Labs …
RIACO Icon Block
riaco-icon-block
RIACO Icon Block add SVG icons as WordPress block with full control over icon selection and style.
JVM Rich Text Icons Developer Profile
5 plugins · 4K total installs
How We Detect JVM Rich Text Icons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/jvm-rich-text-icons/dist/acf.js/wp-content/plugins/jvm-rich-text-icons/css/frontend.css/wp-content/plugins/jvm-rich-text-icons/css/editor.css/wp-content/plugins/jvm-rich-text-icons/dist/acf.jsjvm-rich-text-icons/css/frontend.css?ver=jvm-rich-text-icons/css/editor.css?ver=HTML / DOM Fingerprints
jvm-rich-text-iconjvm-rich-text-icons-select2<!-- WordPress core is in control of block settings. We override this by setting inline CSS. --><!-- Filter hook for inline SVG output --><!-- Review notice timing --><!-- Enable ACF fields -->data-acf-field-idwindow.acf/wp-json/acf/v1/fields/jvm_rich_text_icons<i class="jvm-rich-text-icon<span class="jvm-rich-text-icons-select2">