
Manager for Icomoon Security & Risk Analysis
wordpress.org/plugins/manager-for-icomoonManage icomoon package.
Is Manager for Icomoon Safe to Use in 2026?
Generally Safe
Score 98/100Manager for Icomoon has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'manager-for-icomoon' plugin v2.4 presents a mixed security posture. While it demonstrates good practices such as exclusively using prepared statements for SQL queries and having no bundled libraries, significant concerns arise from its attack surface and output escaping. The presence of two unprotected AJAX handlers is a major security flaw, as it allows unauthenticated users to potentially execute arbitrary code or manipulate plugin functionality. The low percentage of properly escaped output (33%) indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the WordPress admin area or user-facing pages.
The vulnerability history is particularly concerning. Two known CVEs, including a past critical vulnerability related to unrestricted file uploads and XSS, suggest a pattern of exploitable flaws. Although there are currently no unpatched vulnerabilities, the historical severity of past issues indicates that future updates may not sufficiently address all potential risks. The lack of taint analysis data makes it difficult to assess the plugin's internal handling of potentially malicious data, but the static analysis findings strongly suggest an elevated risk profile.
In conclusion, the 'manager-for-icomoon' plugin v2.4 has notable strengths in its database interaction and lack of bundled libraries. However, the unprotected AJAX endpoints, poor output sanitization, and a history of critical vulnerabilities significantly outweigh these positives, marking it as a high-risk plugin requiring immediate attention and scrutiny. Users should exercise extreme caution.
Key Concerns
- Unprotected AJAX handlers
- Low percentage of properly escaped output
- History of critical vulnerability
- History of medium vulnerability
- Attack surface with unprotected entry points
Manager for Icomoon Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Manager for Icomoon <= 2.0 - Unauthenticated Arbitrary File Upload via 'upload'
Manager for Icomoon <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Manager for Icomoon Release Timeline
Manager for Icomoon Code Analysis
Output Escaping
Manager for Icomoon Attack Surface
AJAX Handlers 2
WordPress Hooks 4
Maintenance & Trust
Manager for Icomoon Maintenance & Trust
Maintenance Signals
Community Trust
Manager for Icomoon Alternatives
Big Sea SVG Icons
bsd-svg-icons
Built by designers, for designers. Add SVG images with ease, via a single function or shortcode. Comes with icons from icomoon!
Font Awesome
font-awesome
The official way to use Font Awesome Free or Pro icons on your WordPress site, brought to you by the Font Awesome team.
Skyboot Custom Icons for Elementor
skyboot-custom-icons-for-elementor
Skyboot Custom Icons for Elementor expands your Elementor icon library with 14,300+ icons from 15 packs, fully customizable in Elementor's editor.
Use Any Font | Custom Font Uploader
use-any-font
Upload custom fonts with custom font uploader. Auto converts to woff2 for better performance. Self-hosted, GDPR compliant, and easy custom font plugin
Better Font Awesome
better-font-awesome
The Better Font Awesome plugin for WordPress. Shortcodes, HTML, TinyMCE, various Font Awesome versions, backwards compatibility, CDN speeds, and more.
Manager for Icomoon Developer Profile
3 plugins · 510 total installs
How We Detect Manager for Icomoon
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/manager-for-icomoon/css/icomoon-icons.css/wp-content/plugins/manager-for-icomoon/css/font-awesome.css/wp-content/plugins/manager-for-icomoon/css/manager-for-icomoon.css/wp-content/plugins/manager-for-icomoon/js/manager-for-icomoon.js/wp-content/plugins/manager-for-icomoon/js/jquery.icomoon.js/wp-content/plugins/manager-for-icomoon/js/icomoon.js/wp-content/plugins/manager-for-icomoon/js/manager-for-icomoon.js/wp-content/plugins/manager-for-icomoon/js/jquery.icomoon.js/wp-content/plugins/manager-for-icomoon/js/icomoon.jsmanager-for-icomoon/css/icomoon-icons.css?ver=manager-for-icomoon/css/font-awesome.css?ver=manager-for-icomoon/css/manager-for-icomoon.css?ver=manager-for-icomoon/js/manager-for-icomoon.js?ver=manager-for-icomoon/js/jquery.icomoon.js?ver=manager-for-icomoon/js/icomoon.js?ver=HTML / DOM Fingerprints
manager-for-icomoon-settingsicomoon-icon-selector<!-- START MANAGER FOR ICOMOON SHORTCODE --><!-- END MANAGER FOR ICOMOON SHORTCODE --><!-- MANAGER FOR ICOMOON FONT SELECTION FILE --><!-- MANAGER FOR ICOMOON FONT FAMILY -->data-icomoon-selectormanager_for_icomoon_ajax_object<span class="icomoon-icon-selector" data-icomoon-selector="<i class="icomoon-icon-