
Surbma | Font Awesome Security & Risk Analysis
wordpress.org/plugins/surbma-font-awesomeFont Awesome - The iconic font and CSS toolkit
Is Surbma | Font Awesome Safe to Use in 2026?
Generally Safe
Score 91/100Surbma | Font Awesome has a strong security track record. Known vulnerabilities have been patched promptly.
The surbma-font-awesome plugin, version 3.1, exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, proper handling of SQL queries with prepared statements, and 100% output escaping are commendable practices. Furthermore, the lack of file operations and external HTTP requests reduces potential attack vectors. The plugin also shows no signs of unsanitized taint flows, which is a positive indicator.
However, the plugin's vulnerability history reveals a past medium-severity Cross-Site Scripting (XSS) vulnerability, despite it being currently unpatched. While the static analysis doesn't highlight any immediate XSS flaws in the current version's entry points, the historical pattern suggests a potential for such issues if inputs are not meticulously handled across all functionalities. The presence of a shortcode as the sole entry point is not inherently a risk, but it's the only potential surface that could interact with user-supplied data. The absence of nonce and capability checks on this shortcode, although not explicitly flagged as a weakness by the analysis, represents a missed opportunity to harden the plugin against potential abuse.
In conclusion, while surbma-font-awesome version 3.1 demonstrates strengths in secure coding practices like prepared statements and output escaping, the historical XSS vulnerability and the lack of explicit authorization checks on its single entry point warrant caution. Continuous monitoring and a proactive approach to security updates remain crucial.
Key Concerns
- Medium severity XSS vulnerability in history
- Missing capability checks on shortcode
- Missing nonce checks on shortcode
Surbma | Font Awesome Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Surbma | Font Awesome <= 3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Surbma | Font Awesome Code Analysis
Output Escaping
Surbma | Font Awesome Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Surbma | Font Awesome Maintenance & Trust
Maintenance Signals
Community Trust
Surbma | Font Awesome Alternatives
NM Font Awesome
nm-font-awesome
Wordpress plugin that adds the latest version 5 of Font Awesome into your WordPress project.
Perfect Font Awesome Integration
perfect-font-awesome-integration
Perfectly Integrates latest font awesome icons with your wordpress site as well as adds an Icon insert button in Tiny MCE wordpress editor.
Convert Emoticons Font Awesome
convert-emoticons-font-awesome
Converts emoticons to Font Awesome icons.
Wp Fontawesome by Creareblogs.net
wp-cb-fontawesome
Wp Cb FontAwesome is a plugin to migrate from [FontAwesome](http://www.fontawesome.com "FontAwesome") 4 to 5 in the easiest way possible.
Rundiz Font Awesome
rd-fontawesome
Use Font Awesome from your host and update from GitHub.
Surbma | Font Awesome Developer Profile
27 plugins · 30K total installs
How We Detect Surbma | Font Awesome
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/surbma-font-awesome/assets/css/font-awesome.min.csssurbma-font-awesome/assets/css/font-awesome.min.css?ver=HTML / DOM Fingerprints
fa<i class="fa</i>