Open Icons for ACF (Lite) Security & Risk Analysis

wordpress.org/plugins/open-icons-acf

A beautiful icon picker field for Advanced Custom Fields using Heroicons. Pick from 324 hand-crafted SVG icons.

0 active installs v1.0.0 PHP 7.4+ WP 5.8+ Updated Mar 26, 2026
acfcustom-fieldsheroiconsiconssvg
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Open Icons for ACF (Lite) Safe to Use in 2026?

Generally Safe

Score 100/100

Open Icons for ACF (Lite) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'open-icons-acf' plugin, version 1.0.0, exhibits a strong security posture based on the provided static analysis. The complete absence of identified attack surface vectors like unprotected AJAX handlers, REST API routes, shortcodes, or cron events is a significant positive. Furthermore, the code demonstrates good development practices with 100% of SQL queries utilizing prepared statements and a very high rate of output escaping (99%). The presence of nonce and capability checks (1 and 6 respectively) further indicates a commitment to secure coding standards. The plugin's vulnerability history is also clean, with no recorded CVEs, suggesting a well-maintained or less-targeted codebase.

While the static analysis reveals no immediate critical or high-severity vulnerabilities in taint flows or dangerous functions, there are minor areas for consideration. The presence of file operations (4) and external HTTP requests (2) could theoretically be points of exploitation if not handled with extreme care, though the analysis did not flag them as unsanitized. The single nonce check is adequate for a single entry point, but its overall effectiveness is tied to the specific implementation, which isn't detailed here. The lack of bundled libraries is a positive sign for avoiding known vulnerable components.

In conclusion, 'open-icons-acf' v1.0.0 appears to be a secure plugin with excellent adherence to common WordPress security best practices. The lack of any detected vulnerabilities, both in static analysis and historical data, is a strong indicator of quality. The minor points for file operations and external requests are standard considerations for any plugin and are not flagged as current issues. The overall risk is assessed as very low.

Vulnerabilities
None known

Open Icons for ACF (Lite) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Open Icons for ACF (Lite) Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

Open Icons for ACF (Lite) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
118 escaped
Nonce Checks
1
Capability Checks
6
File Operations
4
External Requests
2
Bundled Libraries
0

Output Escaping

99% escaped119 total outputs
Attack Surface

Open Icons for ACF (Lite) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
filterscript_loader_tagincludes/class-asset-loader.php:198
actionrest_api_initincludes/class-rest.php:21
actionadmin_menuincludes/class-settings.php:18
actionadmin_initincludes/class-settings.php:19
actionadmin_post_openicon_restore_defaultsincludes/class-settings.php:20
actionadmin_noticesopen-icons-acf.php:52
actionplugins_loadedopen-icons-acf.php:64
actionacf/initopen-icons-acf.php:92
actionadmin_enqueue_scriptsopen-icons-acf.php:119
Maintenance & Trust

Open Icons for ACF (Lite) Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 26, 2026
PHP min version7.4
Downloads81

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Open Icons for ACF (Lite) Developer Profile

davidbuilds

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Open Icons for ACF (Lite)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/open-icons-acf/build/acf-open-icons-lite.css/wp-content/plugins/open-icons-acf/build/acf-open-icons-lite.js
Script Paths
/wp-content/plugins/open-icons-acf/build/acf-open-icons-lite.js
Version Parameters
open-icons-acf/build/acf-open-icons-lite.css?ver=open-icons-acf/build/acf-open-icons-lite.js?ver=

HTML / DOM Fingerprints

CSS Classes
acf-field-wrapacf-fieldacf-field-open-icons-lite
Data Attributes
data-field-iddata-field-typedata-acf-field-open-icons-lite
JS Globals
acfOpenIcons
REST Endpoints
/wp-json/open-icons-acf/v1/icons
FAQ

Frequently Asked Questions about Open Icons for ACF (Lite)