Ultimate Icon Shortcodes – LITE Security & Risk Analysis

wordpress.org/plugins/ultimate-icon-shortcodes

This plugin will add a small button to your post / page editor, clicking on that will bring up our visual icon selector. Choose the icon you want and …

10 active installs v1.1 PHP + WP 3+ Updated Oct 22, 2013
brandicofont-awesomefontelicoiconsshortcodes
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ultimate Icon Shortcodes – LITE Safe to Use in 2026?

Generally Safe

Score 85/100

Ultimate Icon Shortcodes – LITE has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The "ultimate-icon-shortcodes" plugin version 1.1 exhibits a strong security posture based on the provided static analysis. The code demonstrates adherence to secure coding practices, with no dangerous functions, 100% of SQL queries using prepared statements, and 100% of outputs properly escaped. Crucially, there are no identified taint flows indicating potential for injection attacks. The absence of known CVEs in its vulnerability history further reinforces this positive assessment, suggesting a history of stable and secure development.

Despite the strong positive indicators, a few areas warrant attention. The plugin has a single entry point via a shortcode, which is not explicitly protected by nonce checks according to the static analysis. While capability checks are present, their effectiveness in preventing unauthorized access to the shortcode's functionality is not detailed here. The lack of external HTTP requests and file operations, along with no bundled libraries, reduces potential attack vectors. However, the absence of nonce checks on the shortcode represents a potential weakness that could be exploited if the shortcode performs sensitive operations.

In conclusion, "ultimate-icon-shortcodes" v1.1 appears to be a well-developed plugin with a solid security foundation, characterized by secure query handling and output escaping, and a clean vulnerability history. The primary concern arises from the potential lack of nonce protection on its sole shortcode entry point, which could be a vector for certain types of attacks if not properly mitigated through capability checks or other server-side validation. Overall, the risk is assessed as low, but vigilance regarding the shortcode's implementation is recommended.

Key Concerns

  • Shortcode without explicit nonce check
Vulnerabilities
None known

Ultimate Icon Shortcodes – LITE Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Ultimate Icon Shortcodes – LITE Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Ultimate Icon Shortcodes – LITE Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[uis] index.php:70
WordPress Hooks 6
actioninitindex.php:32
filtermce_external_pluginsindex.php:39
filtermce_buttonsindex.php:41
actionadmin_print_stylesindex.php:55
actionadmin_print_stylesindex.php:56
actionwp_enqueue_scriptsindex.php:116
Maintenance & Trust

Ultimate Icon Shortcodes – LITE Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedOct 22, 2013
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Ultimate Icon Shortcodes – LITE Developer Profile

Shane Jones

3 plugins · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ultimate Icon Shortcodes – LITE

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ultimate-icon-shortcodes-lite/css/overlay-styles.css/wp-content/plugins/ultimate-icon-shortcodes-lite/css/uis-fonts.css/wp-content/plugins/ultimate-icon-shortcodes-lite/css/uis-fonts-ie7.css
Script Paths
/wp-content/plugins/ultimate-icon-shortcodes-lite/shortcode.js

HTML / DOM Fingerprints

CSS Classes
uis_button
Shortcode Output
<span class=" icon-spin icon-ui-dialog
FAQ

Frequently Asked Questions about Ultimate Icon Shortcodes – LITE