Site Favicon Security & Risk Analysis

wordpress.org/plugins/site-favicon

Add a favicon.

5K active installs v1.0 PHP + WP 5.0+ Updated Jan 21, 2026
faviconfavorites-iconiconsite-icon
99
A · Safe
CVEs total1
Unpatched0
Last CVEMay 30, 2024
Download
Safety Verdict

Is Site Favicon Safe to Use in 2026?

Generally Safe

Score 99/100

Site Favicon has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: May 30, 2024Updated 2mo ago
Risk Assessment

The "site-favicon" v1.0 plugin exhibits a generally good security posture based on the static analysis provided. The absence of any identified dangerous functions, SQL queries not using prepared statements, unescaped output, file operations, external HTTP requests, and the lack of a significant attack surface (entry points) are all positive indicators. The taint analysis also shows no concerning flows, suggesting the code is not immediately vulnerable to common injection attacks through its analyzed paths.

However, the plugin's history is a significant concern. With one known CVE, specifically a Cross-site Scripting (XSS) vulnerability, that was recently patched, it indicates a past weakness. While currently unpatched vulnerabilities are zero, the existence of past XSS issues, even if resolved, suggests potential for similar vulnerabilities to reappear if not thoroughly re-audited. The lack of capability checks and nonce checks in the static analysis, while not a direct problem given the zero entry points, means that if any entry points were to be introduced in future versions, they might lack fundamental security measures.

In conclusion, the current version of "site-favicon" appears to be secure based on the static code review. The primary risk stems from its vulnerability history, particularly the past XSS issue. While the current implementation seems robust, diligent ongoing security review and testing for future versions are highly recommended to prevent recurrence of past vulnerabilities.

Key Concerns

  • Vulnerability history: 1 medium CVE
  • Past XSS vulnerability
  • No capability checks
  • No nonce checks
Vulnerabilities
1

Site Favicon Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-35642medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Site Favicon <= 0.2 - Authenticated (Admin+) Stored Cross-Site Scripting

May 30, 2024 Patched in 0.3 (7d)
Code Analysis
Analyzed Mar 16, 2026

Site Favicon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

Site Favicon Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwp_headsite-favicon.php:19
actioncustomize_registersite-favicon.php:27
Maintenance & Trust

Site Favicon Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJan 21, 2026
PHP min version
Downloads30K

Community Trust

Rating76/100
Number of ratings4
Active installs5K
Developer Profile

Site Favicon Developer Profile

Web Guy

30 plugins · 52K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
629 days
View full developer profile
Detection Fingerprints

How We Detect Site Favicon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/site-favicon/site-favicon.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Site Favicon