Manager for Icomoon Security & Risk Analysis

wordpress.org/plugins/manager-for-icomoon

Manage icomoon package.

400 active installs v2.4 PHP + WP 4.7.4+ Updated Nov 27, 2025
fonticomooniconmanager
98
A · Safe
CVEs total2
Unpatched0
Last CVEMay 8, 2023
Safety Verdict

Is Manager for Icomoon Safe to Use in 2026?

Generally Safe

Score 98/100

Manager for Icomoon has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

2 known CVEsLast CVE: May 8, 2023Updated 5mo ago
Risk Assessment

The 'manager-for-icomoon' plugin v2.4 presents a mixed security posture. While it demonstrates good practices such as exclusively using prepared statements for SQL queries and having no bundled libraries, significant concerns arise from its attack surface and output escaping. The presence of two unprotected AJAX handlers is a major security flaw, as it allows unauthenticated users to potentially execute arbitrary code or manipulate plugin functionality. The low percentage of properly escaped output (33%) indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the WordPress admin area or user-facing pages.

The vulnerability history is particularly concerning. Two known CVEs, including a past critical vulnerability related to unrestricted file uploads and XSS, suggest a pattern of exploitable flaws. Although there are currently no unpatched vulnerabilities, the historical severity of past issues indicates that future updates may not sufficiently address all potential risks. The lack of taint analysis data makes it difficult to assess the plugin's internal handling of potentially malicious data, but the static analysis findings strongly suggest an elevated risk profile.

In conclusion, the 'manager-for-icomoon' plugin v2.4 has notable strengths in its database interaction and lack of bundled libraries. However, the unprotected AJAX endpoints, poor output sanitization, and a history of critical vulnerabilities significantly outweigh these positives, marking it as a high-risk plugin requiring immediate attention and scrutiny. Users should exercise extreme caution.

Key Concerns

  • Unprotected AJAX handlers
  • Low percentage of properly escaped output
  • History of critical vulnerability
  • History of medium vulnerability
  • Attack surface with unprotected entry points
Vulnerabilities
2 published

Manager for Icomoon Security Vulnerabilities

CVEs by Year

2 CVEs in 2023
2023
Patched Has unpatched

Severity Breakdown

Critical
1
Medium
1

2 total CVEs

CVE-2023-29386critical · 9.8Unrestricted Upload of File with Dangerous Type

Manager for Icomoon <= 2.0 - Unauthenticated Arbitrary File Upload via 'upload'

May 8, 2023 Patched in 2.1 (260d)
CVE-2023-29387medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Manager for Icomoon <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

May 4, 2023 Patched in 2.2 (264d)
Version History

Manager for Icomoon Release Timeline

v2.4Current
v2.3.10
v2.3.6
v2.3.5
v2.3.4
v2.3.3
v2.3.1
v2.3
v2.2.1
v2.2
Code Analysis
Analyzed Mar 16, 2026

Manager for Icomoon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
86
42 escaped
Nonce Checks
1
Capability Checks
1
File Operations
9
External Requests
0
Bundled Libraries
0

Output Escaping

33% escaped128 total outputs
Attack Surface
2 unprotected

Manager for Icomoon Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

noprivwp_ajax_m4i_gutenberg_modal_insert_iconclass\gutenberg.class.php:9
authwp_ajax_m4i_gutenberg_modal_insert_iconclass\gutenberg.class.php:10
WordPress Hooks 4
actioninitclass\gutenberg.class.php:7
actionadmin_menuclass\plugin.class.php:18
actionadmin_initclass\settings.class.php:9
filterwidget_textmanagerforicomoon.php:57
Maintenance & Trust

Manager for Icomoon Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 27, 2025
PHP min version
Downloads10K

Community Trust

Rating100/100
Number of ratings5
Active installs400
Developer Profile

Manager for Icomoon Developer Profile

albedo0

3 plugins · 510 total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
177 days
View full developer profile
Detection Fingerprints

How We Detect Manager for Icomoon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/manager-for-icomoon/css/icomoon-icons.css/wp-content/plugins/manager-for-icomoon/css/font-awesome.css/wp-content/plugins/manager-for-icomoon/css/manager-for-icomoon.css/wp-content/plugins/manager-for-icomoon/js/manager-for-icomoon.js/wp-content/plugins/manager-for-icomoon/js/jquery.icomoon.js/wp-content/plugins/manager-for-icomoon/js/icomoon.js
Script Paths
/wp-content/plugins/manager-for-icomoon/js/manager-for-icomoon.js/wp-content/plugins/manager-for-icomoon/js/jquery.icomoon.js/wp-content/plugins/manager-for-icomoon/js/icomoon.js
Version Parameters
manager-for-icomoon/css/icomoon-icons.css?ver=manager-for-icomoon/css/font-awesome.css?ver=manager-for-icomoon/css/manager-for-icomoon.css?ver=manager-for-icomoon/js/manager-for-icomoon.js?ver=manager-for-icomoon/js/jquery.icomoon.js?ver=manager-for-icomoon/js/icomoon.js?ver=

HTML / DOM Fingerprints

CSS Classes
manager-for-icomoon-settingsicomoon-icon-selector
HTML Comments
<!-- START MANAGER FOR ICOMOON SHORTCODE --><!-- END MANAGER FOR ICOMOON SHORTCODE --><!-- MANAGER FOR ICOMOON FONT SELECTION FILE --><!-- MANAGER FOR ICOMOON FONT FAMILY -->
Data Attributes
data-icomoon-selector
JS Globals
manager_for_icomoon_ajax_object
Shortcode Output
<span class="icomoon-icon-selector" data-icomoon-selector="<i class="icomoon-icon-
FAQ

Frequently Asked Questions about Manager for Icomoon