Noio Iconized Bookmarks Security & Risk Analysis
wordpress.org/plugins/noio-iconized-bookmarksPlugin that allows you to automatically add favicons to your blog's links.
Is Noio Iconized Bookmarks Safe to Use in 2026?
Generally Safe
Score 85/100Noio Iconized Bookmarks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "noio-iconized-bookmarks" plugin version 1.0.1 exhibits a concerning security posture despite having a seemingly small attack surface. While the static analysis reports zero AJAX handlers, REST API routes, shortcodes, or cron events without authentication, this lack of entry points might also contribute to the absence of built-in security checks like capability checks and nonce checks. The plugin uses the `create_function` which is deprecated and considered a security risk due to its ability to execute arbitrary PHP code. Furthermore, the taint analysis revealed two high-severity flows with unsanitized paths, indicating potential vulnerabilities related to file operations or external requests where input might not be properly validated before being used in a sensitive operation. The lack of output escaping for all 36 outputs is a significant concern, as it opens the door for cross-site scripting (XSS) vulnerabilities if any user-controlled data is displayed without proper sanitization. The complete absence of recorded CVEs is a positive sign, suggesting the plugin has not had publicly disclosed vulnerabilities. However, this does not negate the issues found in the static analysis. The overall security posture is weakened by the presence of dangerous functions, unsanitized taint flows, and universal output escaping failures, despite the limited attack surface and clean CVE history.
Key Concerns
- High severity taint flows with unsanitized paths
- Dangerous function 'create_function' used
- 100% of outputs are not properly escaped
- No nonce checks
- No capability checks
Noio Iconized Bookmarks Security Vulnerabilities
Noio Iconized Bookmarks Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Noio Iconized Bookmarks Attack Surface
WordPress Hooks 3
Maintenance & Trust
Noio Iconized Bookmarks Maintenance & Trust
Maintenance Signals
Community Trust
Noio Iconized Bookmarks Alternatives
FAVIROLL – FAVIcons for blogROLL
faviroll
This plugin convert the favicon.ico from the blogroll sites into PNG images and save this in a local cache file. The conversion process works just on …
Blogroll Links Favicons
blogroll-links-favicons
Automatically adds favicons to blogroll/bookmark links.
Blogroll Links
blogroll-links
Display your blogroll links anywhere in posts or pages using a simple shortcode.
Blogroll Widget with RSS Feeds
blogroll-rss-widget
Displays the recent posts of your blogroll links via RSS Feeds in a customizable sidebar widget
Bookmarks Shortcode
bookmarks-shortcode
Creates shortcodes that will generate an unordered list of your WordPress links (bookmarks).
Noio Iconized Bookmarks Developer Profile
1 plugin · 10 total installs
How We Detect Noio Iconized Bookmarks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/noio-iconized-bookmarks/empty.png/wp-content/plugins/noio-iconized-bookmarks/notfound.png/wp-content/plugins/noio-iconized-bookmarks/default.gif/wp-content/plugins/noio-iconized-bookmarks/select.pngnoio-iconized-bookmarks/empty.png?ver=noio-iconized-bookmarks/notfound.png?ver=noio-iconized-bookmarks/default.gif?ver=noio-iconized-bookmarks/select.png?ver=noio-iconized-bookmarks/noio_iconized_bookmarks.php?ver=HTML / DOM Fingerprints
iconized_bookmarkswidget_args