KitIcon WordPress Gutenberg Icon Block. Security & Risk Analysis

wordpress.org/plugins/kiticon-icon-block

KitIcon is icon block for WordPress Gutenberg Block.

10 active installs v1.0.0 PHP 5.4+ WP 5.0+ Updated Sep 8, 2020
gutenberg-addon-icongutenberg-icongutenberg-icon-blockicon-blocksicon-block
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is KitIcon WordPress Gutenberg Icon Block. Safe to Use in 2026?

Generally Safe

Score 85/100

KitIcon WordPress Gutenberg Icon Block. has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

This plugin exhibits a generally strong security posture based on the static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events, especially without authentication checks, significantly limits its attack surface. Furthermore, the complete absence of dangerous functions and SQL queries not using prepared statements are excellent indicators of secure coding practices. The fact that there are no known vulnerabilities (CVEs) and no recorded vulnerability history further contributes to this positive assessment.

However, there are a few areas for improvement. The presence of two file operations without further context raises a slight concern, as these could potentially be misused if not handled securely. More importantly, the fact that only 50% of output is properly escaped means that the other half could be vulnerable to Cross-Site Scripting (XSS) attacks. The lack of nonce checks and capability checks, while not directly exploitable given the current attack surface, represents missed opportunities for robust security, especially if the plugin's functionality were to expand in the future.

In conclusion, kiticon-icon-block v1.0.0 appears to be a relatively secure plugin with a minimal attack surface and good data sanitization practices for SQL. The primary concern lies in the unescaped output, which presents a potential XSS risk. Addressing this and potentially implementing basic security checks like nonces and capabilities would further enhance its security profile.

Key Concerns

  • Partial output escaping
  • File operations without context
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

KitIcon WordPress Gutenberg Icon Block. Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

KitIcon WordPress Gutenberg Icon Block. Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped4 total outputs
Attack Surface

KitIcon WordPress Gutenberg Icon Block. Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterblock_categoriesfunction\blocks-cat.php:4
actionplugins_loadedfunction\carbon-loader.php:9
actionwp_footerfunction\kiticon-scripts.php:4
actioncarbon_fields_register_fieldsincludes\icon-block\block-kiticon.php:10
Maintenance & Trust

KitIcon WordPress Gutenberg Icon Block. Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedSep 8, 2020
PHP min version5.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

KitIcon WordPress Gutenberg Icon Block. Developer Profile

KitBug

4 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect KitIcon WordPress Gutenberg Icon Block.

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kiticon-icon-block/kiticon-icons.css/wp-content/plugins/kiticon-icon-block/includes/icon-block/icons/

HTML / DOM Fingerprints

CSS Classes
kiticon-areakiticon-icon
Data Attributes
kiticon_icon_colorkiticon_icon_font_sizekiticon_icon_alignkiticon_icon
Shortcode Output
<div class="kiticon-area"><div class="kiticon-icon" style="
FAQ

Frequently Asked Questions about KitIcon WordPress Gutenberg Icon Block.