SS Font Awesome Icon Security & Risk Analysis

wordpress.org/plugins/ss-font-awesome-icon

Easiest way to integrate Font Awesome Icon in any post or widget.

200 active installs v4.1.3 PHP + WP 4.0.0+ Updated Aug 29, 2020
font-awesome-icon-inside-postfont-awesome-icon-short-codespost-inside-iconstotal-font-awesome-icons
63
C · Use Caution
CVEs total1
Unpatched1
Last CVESep 5, 2025
Safety Verdict

Is SS Font Awesome Icon Safe to Use in 2026?

Use With Caution

Score 63/100

SS Font Awesome Icon has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Sep 5, 2025Updated 5yr ago
Risk Assessment

The 'ss-font-awesome-icon' plugin v4.1.3 exhibits a mixed security posture. On the positive side, the static analysis indicates good coding practices. There are no identified dangerous functions, all SQL queries use prepared statements, and output is properly escaped. Furthermore, the plugin does not perform file operations or external HTTP requests, and there are no critical or high-severity taint flows. However, the presence of one unpatched medium-severity vulnerability (CVE) is a significant concern, suggesting a past issue that has not been remediated in this version.

The plugin's attack surface is minimal, with only one shortcode as an entry point, and notably, it has no unprotected entry points according to the static analysis. The absence of nonce checks and capability checks, while not immediately problematic given the limited attack surface and lack of direct input handling identified in static analysis, could become a concern if the plugin were to evolve or integrate with other systems that expose its functionality more broadly. The vulnerability history, specifically the past Cross-site Scripting (XSS) vulnerability, indicates a potential for input sanitization weaknesses, even though the current static analysis doesn't reveal such issues in this specific version.

In conclusion, while the current version of 'ss-font-awesome-icon' v4.1.3 demonstrates strong adherence to several secure coding principles, the single unpatched medium-severity vulnerability introduces a notable risk. Users should prioritize updating to a version that addresses this known CVE. The minimal attack surface and absence of critical code signals are strengths, but the past vulnerability pattern warrants vigilance.

Key Concerns

  • Unpatched medium severity CVE
Vulnerabilities
1

SS Font Awesome Icon Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-58837medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SS Font Awesome Icon <= 4.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 5, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

SS Font Awesome Icon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

SS Font Awesome Icon Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[icon] fa-icons.php:52
WordPress Hooks 3
actionwp_enqueue_scriptsfa-icons.php:24
filterwidget_textfa-icons.php:28
actioninitfa-icons.php:54
Maintenance & Trust

SS Font Awesome Icon Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.0
Last updatedAug 29, 2020
PHP min version
Downloads8K

Community Trust

Rating100/100
Number of ratings1
Active installs200
Alternatives

SS Font Awesome Icon Alternatives

No alternatives data available yet.

Developer Profile

SS Font Awesome Icon Developer Profile

Shiful H

3 plugins · 250 total installs

79
trust score
Avg Security Score
78/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SS Font Awesome Icon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ss-font-awesome-icon/css/style.css

HTML / DOM Fingerprints

CSS Classes
fafa-
Shortcode Output
<i style="background:;color:;font-size:px;padding:
FAQ

Frequently Asked Questions about SS Font Awesome Icon