SVG Icons Security & Risk Analysis
wordpress.org/plugins/shp-iconThis plugin allows you to use SVG icons within WordPress as shortcode and/or as Gutenberg Block and adds SVG support with the SVG-Sanitizer library.
Is SVG Icons Safe to Use in 2026?
Generally Safe
Score 100/100SVG Icons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "shp-icon" v1.2.2 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, exclusively using prepared statements, and a high percentage of properly escaped output. There are also no known vulnerabilities (CVEs) associated with this plugin, suggesting a relatively stable history. However, significant concerns arise from its attack surface. The presence of two AJAX handlers, both lacking authentication checks, presents a direct pathway for potential unauthorized actions. Furthermore, the taint analysis reveals three flows with unsanitized paths, which, while not flagged as critical or high severity in this specific analysis, still represent a potential risk for injection vulnerabilities if input is not meticulously handled downstream. The absence of capability checks on entry points is also a notable weakness.
Key Concerns
- AJAX handlers without auth checks
- Flows with unsanitized paths
- No capability checks on entry points
- Nonce checks present but limited
SVG Icons Security Vulnerabilities
SVG Icons Code Analysis
Output Escaping
Data Flow Analysis
SVG Icons Attack Surface
AJAX Handlers 2
WordPress Hooks 15
Maintenance & Trust
SVG Icons Maintenance & Trust
Maintenance Signals
Community Trust
SVG Icons Alternatives
Popular Brand Icons – Simple Icons
simple-icons
An easy to use lightweight SVG icons plugin with over 1500+ brand icons. Use these icons in your menus, widgets, posts, or pages.
WP and Divi Icons
wp-and-divi-icons
Add 660+ optimized, scalable SVG icons for your WordPress site. Use them anywhere and easily customize their color and size to suit your needs.
Hugeicons
hugeicons
Add beautiful Hugeicons to your WordPress site with an easy-to-use icon picker for both classic and block editors.
Omni Icon – Modern SVG icon library for WordPress
omni-icon
A modern SVG icon library for WordPress with support for custom uploads and 200,000+ Iconify icons across block editor, page builders, and themes.
Spectre Icons
spectre-icons
Curated SVG icon libraries for Elementor with fast manifests, inline rendering, and color controls.
SVG Icons Developer Profile
3 plugins · 320 total installs
How We Detect SVG Icons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shp-icon/assets/gutenberg/blocks.js/wp-content/plugins/shp-icon/assets/scripts/admin.js/wp-content/plugins/shp-icon/assets/scripts/ui.js/wp-content/plugins/shp-icon/assets/styles/ui.css/wp-content/plugins/shp-icon/assets/styles/admin.css/wp-content/plugins/shp-icon/assets/gutenberg/blocks.js/wp-content/plugins/shp-icon/assets/scripts/admin.js/wp-content/plugins/shp-icon/assets/scripts/ui.js/wp-content/plugins/shp-icon/assets/gutenberg/blocks.js?ver=/wp-content/plugins/shp-icon/assets/scripts/admin.js?ver=/wp-content/plugins/shp-icon/assets/scripts/ui.js?ver=/wp-content/plugins/shp-icon/assets/styles/ui.css?ver=/wp-content/plugins/shp-icon/assets/styles/admin.css?ver=HTML / DOM Fingerprints
window.shp_icon_data