Bootstrap and Font Awesome by HocWP Team Security & Risk Analysis

wordpress.org/plugins/sb-tbfa

The easiest way to load Twitter Bootstrap and Font Awesome on your WordPress site.

40 active installs v2.0.0 PHP + WP 4.7+ Updated Sep 26, 2017
bootstrapfont-awesomehocwphocwp-team
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bootstrap and Font Awesome by HocWP Team Safe to Use in 2026?

Generally Safe

Score 85/100

Bootstrap and Font Awesome by HocWP Team has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "sb-tbfa" v2.0.0 plugin exhibits an excellent security posture. The static analysis reveals no identified attack surface in terms of AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the code signals indicate a lack of dangerous functions, all SQL queries are prepared, and all outputs are properly escaped. There are no file operations, external HTTP requests, or indications of missing nonce or capability checks. The taint analysis also shows no identified flows with unsanitized paths. This suggests a well-written and secure plugin from a code perspective.

Crucially, the vulnerability history for "sb-tbfa" is completely clean, with zero recorded CVEs of any severity. This lack of historical vulnerabilities, combined with the robust static analysis findings, strongly suggests that the developers have a mature approach to security. The plugin appears to follow best practices consistently. While the absence of any identified entry points or potential vulnerabilities is a significant strength, it's important to acknowledge that no static analysis is perfect. However, the current data provides a high degree of confidence in the security of this plugin version. The only minor area for consideration, though not a deduction based on the data, is the complete absence of any non-empty entry points, which might imply very limited functionality, or that further analysis would be required to confirm all potential interaction vectors. Nevertheless, based solely on the provided data, this plugin is exceptionally secure.

Vulnerabilities
None known

Bootstrap and Font Awesome by HocWP Team Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Bootstrap and Font Awesome by HocWP Team Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Bootstrap and Font Awesome by HocWP Team Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwp_enqueue_scriptssb-tbfa.php:23
Maintenance & Trust

Bootstrap and Font Awesome by HocWP Team Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedSep 26, 2017
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs40
Developer Profile

Bootstrap and Font Awesome by HocWP Team Developer Profile

skylarkcob

8 plugins · 190 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bootstrap and Font Awesome by HocWP Team

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sb-tbfa/lib/font-awesome/css/font-awesome.min.css/wp-content/plugins/sb-tbfa/lib/bootstrap/css/bootstrap.min.css/wp-content/plugins/sb-tbfa/lib/bootstrap/js/bootstrap.min.js
Script Paths
/wp-content/plugins/sb-tbfa/lib/bootstrap/js/bootstrap.min.js

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Bootstrap and Font Awesome by HocWP Team