
Advanced Typekit Security & Risk Analysis
wordpress.org/plugins/advanced-typekitAllows you to add Typekit fonts to your site, by targetting them to specific elements using css selectors from the admin panel.
Is Advanced Typekit Safe to Use in 2026?
Use With Caution
Score 64/100Advanced Typekit has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'advanced-typekit' plugin version 1.0.1 exhibits a concerning security posture due to several critical findings. While it doesn't appear to use dangerous functions or engage in raw SQL queries, a significant risk stems from its unprotected AJAX handler. This entry point lacks any authentication or capability checks, making it a prime target for unauthorized actions. Furthermore, the complete absence of output escaping across all identified outputs is a major weakness, strongly suggesting a high susceptibility to Cross-Site Scripting (XSS) vulnerabilities. The plugin's vulnerability history, specifically a known medium-severity XSS vulnerability that remains unpatched, amplifies these concerns. This pattern indicates a lack of proactive security maintenance. Despite the positive note on SQL practices, the combination of an unprotected attack surface, widespread output escaping failures, and an existing unpatched vulnerability paints a picture of a plugin that requires immediate attention and remediation.
Key Concerns
- Unprotected AJAX handler
- No output escaping
- Unpatched CVE
- No capability checks
- No nonce checks
Advanced Typekit Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Advanced Typekit <= 1.0.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Advanced Typekit Code Analysis
Output Escaping
Advanced Typekit Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
Advanced Typekit Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Typekit Alternatives
Easy Google Fonts
easy-google-fonts
Adds google fonts to any theme without coding and integrates with the WordPress Customizer automatically for a realtime live preview.
Dehkadeh Fonts
dehkadeh-fonts
This plugin help you to set persian fonts and size for different parts of the theme via wordpress customizer as easily. Also you can set the custom fo …
Google Webfonts For Woo Framework
google-fonts-for-woo-framework
Give the WooThemes framework access to the full range of current Google Webfonts.
No Google Fonts
no-google-fonts
Prevent Google fonts from loading on the frontend of the website.
Fonts Plugin | Use Google Fonts, Adobe Fonts or Upload Fonts
olympus-google-fonts
The easiest to customize fonts in WordPress. Optimized for Speed. 1000+ font choices. Supports Google Fonts, Adobe Fonts and Upload Fonts.
Advanced Typekit Developer Profile
7 plugins · 130 total installs
How We Detect Advanced Typekit
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
advanced-typekit/advanced-typekit.phpadvanced-typekit/advanced-typekit.php?ver=HTML / DOM Fingerprints
advanced-typekit-options<!-- <th class="manage-column check-column" scope="col" style="width:5em; text-align:center;">Enabled</th> --><!-- <th class="check-column" scope="row" style="padding:15px 10px;"><input type="checkbox" value="advanced-typekit/advanced-typekit.php" name="checked[]"></th> -->advanced_typekit[api_key]advanced_typekit[enabled]advanced_typekit[data][][selectors]advanced_typekit[data][][extra_css]WebFontConfig/wp-json/advanced-typekit