Move Site Icon To Settings Security & Risk Analysis

wordpress.org/plugins/move-site-icon-to-settings

Adds the site icon option to the general settings page

50 active installs v1.1 PHP + WP 4.3+ Updated Dec 11, 2015
customizersite-icon
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Move Site Icon To Settings Safe to Use in 2026?

Generally Safe

Score 85/100

Move Site Icon To Settings has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The plugin "move-site-icon-to-settings" v1.1 exhibits a generally strong security posture based on the provided static analysis. There are no identified vulnerabilities in its history, and the code shows good practices such as the exclusive use of prepared statements for SQL queries and a high percentage of properly escaped output. The absence of external HTTP requests, shortcodes, cron events, and REST API routes further limits the potential attack surface. Furthermore, the analysis indicates no dangerous functions or unsanitized paths in taint flows.

However, a key area of concern is the complete lack of capability checks for any of its entry points. While the static analysis reports zero unprotected entry points (suggesting all might be protected by default WordPress hooks or checks not explicitly detailed), the absence of explicit capability checks is a significant omission. This could potentially lead to privilege escalation if not handled implicitly by WordPress core. The presence of nonces is positive, but these are often paired with capability checks for robust authorization.

In conclusion, the plugin demonstrates good technical coding hygiene regarding data sanitization and SQL injection prevention. Its clean vulnerability history is also a positive indicator. The primary weakness lies in the lack of explicit capability checks, which, if not properly mitigated by WordPress's default behavior for its hooks, could represent a security risk. A thorough review of how its limited entry points are handled by WordPress core would be necessary to definitively assess this risk.

Key Concerns

  • Missing capability checks
Vulnerabilities
None known

Move Site Icon To Settings Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Move Site Icon To Settings Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
35 escaped
Nonce Checks
2
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

78% escaped45 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
crop_page (class-msits-site-icon.php:326)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Move Site Icon To Settings Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionadmin_menuclass-msits-site-icon.php:121
filterdisplay_media_statesclass-msits-site-icon.php:122
actionadmin_initclass-msits-site-icon.php:123
actionadmin_initclass-msits-site-icon.php:124
actionadmin_enqueue_scriptsclass-msits-site-icon.php:125
actionadmin_print_styles-options-general.phpclass-msits-site-icon.php:127
actiondelete_optionclass-msits-site-icon.php:129
actiondelete_attachmentclass-msits-site-icon.php:130
filterget_post_metadataclass-msits-site-icon.php:131
filterintermediate_image_sizes_advancedclass-msits-site-icon.php:434
filterintermediate_image_sizesclass-msits-site-icon.php:561
filterintermediate_image_sizesclass-msits-site-icon.php:574
filterintermediate_image_sizes_advancedclass-msits-site-icon.php:717
Maintenance & Trust

Move Site Icon To Settings Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedDec 11, 2015
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings4
Active installs50
Developer Profile

Move Site Icon To Settings Developer Profile

gregreindel

1 plugin · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Move Site Icon To Settings

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/move-site-icon-to-settings/js/site-icon-crop.js/wp-content/plugins/move-site-icon-to-settings/css/site-icon-admin.css
Script Paths
/wp-content/plugins/move-site-icon-to-settings/js/site-icon-crop.js
Version Parameters
move-site-icon-to-settings/js/site-icon-crop.js?ver=move-site-icon-to-settings/css/site-icon-admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
site-icon-shellsite-icon-contentsite-icon-imagesite-icon-metasite-icon-updatesite-icon-removesite-icon-info
Data Attributes
id="site-icon"id="site-icon-update"id="site-icon-remove"
FAQ

Frequently Asked Questions about Move Site Icon To Settings