
Shortcode for Font Awesome Security & Risk Analysis
wordpress.org/plugins/shortcode-for-font-awesomeInsert Shortcode for Font Awesome in Editor. Here the pure Shortcode is generated. No Font Awesome Files are included. These must already be loaded in …
Is Shortcode for Font Awesome Safe to Use in 2026?
Generally Safe
Score 92/100Shortcode for Font Awesome has a strong security track record. Known vulnerabilities have been patched promptly.
The "shortcode-for-font-awesome" plugin exhibits a generally good security posture based on the static analysis. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and proper output escaping are significant strengths. Furthermore, the limited attack surface, consisting of only one shortcode and no unprotected entry points, reduces the immediate risk. The lack of file operations and external HTTP requests further enhances its security profile.
However, the plugin's vulnerability history reveals a past medium-severity Cross-Site Scripting (XSS) vulnerability, last patched in January 2023. While currently unpatched CVEs are zero, this history indicates a potential for input sanitization issues that could be exploited. The static analysis did not reveal any immediate taint flows or unsanitized paths, which is positive, but the presence of a past XSS suggests that the codebase may not be entirely free from such risks, particularly if new features are added or existing ones are modified without thorough security reviews.
In conclusion, the plugin is relatively well-secured in its current state, with strong adherence to secure coding practices in its static analysis. The primary concern stems from its vulnerability history, specifically the past XSS. While there are no currently unpatched CVEs, this past incident warrants ongoing vigilance. Users should ensure they are running the latest version, which presumably contains the patch for the historical vulnerability, and consider the possibility of similar vulnerabilities in future updates if development practices are not consistently rigorous.
Key Concerns
- Past medium severity XSS vulnerability
- No nonce checks present
- No capability checks present
Shortcode for Font Awesome Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Shortcode for Font Awesome <= 1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Shortcode for Font Awesome Code Analysis
Output Escaping
Shortcode for Font Awesome Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Shortcode for Font Awesome Maintenance & Trust
Maintenance Signals
Community Trust
Shortcode for Font Awesome Alternatives
WP Fontallic Easypromoweb
wp-fontallic-easypromoweb
Font Awesome Icons and more in the visual editor with filter-search and rich content editing at your fingertips
Ultimate Icon Shortcodes – LITE
ultimate-icon-shortcodes
This plugin will add a small button to your post / page editor, clicking on that will bring up our visual icon selector. Choose the icon you want and …
Creative FA and BS Icons Shortcode
creative-fa-and-bs-icons-shortcode
This plugin Allows you to add Font-Awesome and Bootstrap Icons Easily using shortcode. Just install and activate this plugin and use shortcode for usi …
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
MW WP Form
mw-wp-form
MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …
Shortcode for Font Awesome Developer Profile
1 plugin · 700 total installs
How We Detect Shortcode for Font Awesome
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
fa-fas<i class="fas fa-