Rundiz Font Awesome Security & Risk Analysis

wordpress.org/plugins/rd-fontawesome

Use Font Awesome from your host and update from GitHub.

0 active installs v1.0.6 PHP 7.0+ WP 5.0+ Updated Dec 18, 2025
font-awesomefontawesomeicons
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Rundiz Font Awesome Safe to Use in 2026?

Generally Safe

Score 100/100

Rundiz Font Awesome has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The rd-fontawesome v1.0.6 plugin exhibits a generally good security posture, primarily due to the absence of known vulnerabilities and a strong emphasis on secure coding practices in its static analysis. All identified entry points, including AJAX handlers, are protected by nonce and capability checks, which significantly reduces the risk of unauthorized access or execution. The plugin also exclusively uses prepared statements for SQL queries, a critical safeguard against SQL injection. Furthermore, the lack of critical or high-severity taint analysis findings suggests that sensitive data is likely being handled with appropriate sanitization and validation.

However, there are minor areas for improvement. While 81% of output is properly escaped, the remaining 19% could potentially lead to cross-site scripting (XSS) vulnerabilities if the unescaped output contains user-controlled data. Additionally, the presence of file operations and external HTTP requests, while not inherently insecure, warrants careful scrutiny to ensure they are implemented without vulnerabilities. The plugin's history of zero vulnerabilities is a very positive indicator of ongoing security diligence, but it's important to maintain this vigilance, especially with unescaped outputs and potential external interactions.

In conclusion, rd-fontawesome v1.0.6 appears to be a relatively secure plugin. Its robust authentication and authorization mechanisms for entry points, along with the safe handling of database queries, are commendable. The primary concern stems from the unescaped output, which, while not currently a confirmed vulnerability, represents a potential risk that should be addressed to achieve a near-perfect security score. The absence of any historical vulnerabilities is a significant strength, suggesting the developers prioritize security.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Rundiz Font Awesome Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Rundiz Font Awesome Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
13 escaped
Nonce Checks
5
Capability Checks
6
File Operations
3
External Requests
4
Bundled Libraries
0

Output Escaping

81% escaped16 total outputs
Attack Surface

Rundiz Font Awesome Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 5

authwp_ajax_rdfontawesome_installlatestversionApp\Controllers\Admin\SettingsAjax.php:189
authwp_ajax_rdfontawesome_retrievelatestversionApp\Controllers\Admin\SettingsAjax.php:190
authwp_ajax_rdfontawesome_savesettingsApp\Controllers\Admin\SettingsAjax.php:191
authwp_ajax_rdfontawesome_testghpersonalaccesstokenApp\Controllers\Admin\SettingsAjax.php:192
authwp_ajax_rdfontawesome_uninstallfontawesomeApp\Controllers\Admin\SettingsAjax.php:193
WordPress Hooks 8
actioninitApp\App.php:34
filterplugin_action_linksApp\Controllers\Admin\Activation.php:53
filterplugin_row_metaApp\Controllers\Admin\Activation.php:55
actionadmin_menuApp\Controllers\Admin\Settings.php:155
actionwp_enqueue_scriptsApp\Controllers\Front\Hooks\EnqueueDequeue.php:126
actionwp_enqueue_scriptsApp\Controllers\Front\Hooks\EnqueueDequeue.php:129
actionwp_enqueue_scriptsApp\Controllers\Front\Hooks\EnqueueDequeue.php:132
actionwp_print_scriptsApp\Controllers\Front\Hooks\PrintScriptsScanDequeue.php:30
Maintenance & Trust

Rundiz Font Awesome Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedDec 18, 2025
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Rundiz Font Awesome Developer Profile

vee

7 plugins · 2K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Rundiz Font Awesome

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rd-fontawesome/assets/css/admin/settings.css/wp-content/plugins/rd-fontawesome/assets/js/admin/settings.js
Script Paths
/wp-content/plugins/rd-fontawesome/assets/js/admin/settings.js
Version Parameters
rd-fontawesome/assets/css/admin/settings.css?ver=rd-fontawesome/assets/js/admin/settings.js?ver=

HTML / DOM Fingerprints

JS Globals
RdFontAwesomeSettingsObject
FAQ

Frequently Asked Questions about Rundiz Font Awesome