Surbma | Font Awesome Security & Risk Analysis

wordpress.org/plugins/surbma-font-awesome

Font Awesome - The iconic font and CSS toolkit

90 active installs v3.1 PHP 7.4+ WP 5.1+ Updated Dec 30, 2024
font-awesomefontawesomeicon-fonticons
91
A · Safe
CVEs total1
Unpatched0
Last CVENov 8, 2024
Safety Verdict

Is Surbma | Font Awesome Safe to Use in 2026?

Generally Safe

Score 91/100

Surbma | Font Awesome has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 8, 2024Updated 1yr ago
Risk Assessment

The surbma-font-awesome plugin, version 3.1, exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, proper handling of SQL queries with prepared statements, and 100% output escaping are commendable practices. Furthermore, the lack of file operations and external HTTP requests reduces potential attack vectors. The plugin also shows no signs of unsanitized taint flows, which is a positive indicator.

However, the plugin's vulnerability history reveals a past medium-severity Cross-Site Scripting (XSS) vulnerability, despite it being currently unpatched. While the static analysis doesn't highlight any immediate XSS flaws in the current version's entry points, the historical pattern suggests a potential for such issues if inputs are not meticulously handled across all functionalities. The presence of a shortcode as the sole entry point is not inherently a risk, but it's the only potential surface that could interact with user-supplied data. The absence of nonce and capability checks on this shortcode, although not explicitly flagged as a weakness by the analysis, represents a missed opportunity to harden the plugin against potential abuse.

In conclusion, while surbma-font-awesome version 3.1 demonstrates strengths in secure coding practices like prepared statements and output escaping, the historical XSS vulnerability and the lack of explicit authorization checks on its single entry point warrant caution. Continuous monitoring and a proactive approach to security updates remain crucial.

Key Concerns

  • Medium severity XSS vulnerability in history
  • Missing capability checks on shortcode
  • Missing nonce checks on shortcode
Vulnerabilities
1

Surbma | Font Awesome Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-51798medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Surbma | Font Awesome <= 3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Nov 8, 2024 Patched in 3.1 (60d)
Code Analysis
Analyzed Mar 16, 2026

Surbma | Font Awesome Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

Surbma | Font Awesome Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[fa] surbma-font-awesome.php:36
WordPress Hooks 2
actioninitsurbma-font-awesome.php:23
actionwp_enqueue_scriptssurbma-font-awesome.php:27
Maintenance & Trust

Surbma | Font Awesome Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 30, 2024
PHP min version7.4
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs90
Developer Profile

Surbma | Font Awesome Developer Profile

Surbma

27 plugins · 30K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
127 days
View full developer profile
Detection Fingerprints

How We Detect Surbma | Font Awesome

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/surbma-font-awesome/assets/css/font-awesome.min.css
Version Parameters
surbma-font-awesome/assets/css/font-awesome.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
fa
Shortcode Output
<i class="fa</i>
FAQ

Frequently Asked Questions about Surbma | Font Awesome