
hanapaena's Lite – Font & Style Manager – DSGVO/GDPR Security & Risk Analysis
wordpress.org/plugins/ao-lfsmanagerDas Plugin Lite - Font & Style Manager ist die perfekte Lösung für alle, die sich der aktuellen Abmahnwelle, bezüglich Google-Schriftarten entzieh …
Is hanapaena's Lite – Font & Style Manager – DSGVO/GDPR Safe to Use in 2026?
Generally Safe
Score 85/100hanapaena's Lite – Font & Style Manager – DSGVO/GDPR has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ao-lfsmanager" v2.1 plugin exhibits a generally good security posture based on the provided static analysis. The absence of identified attack surface vectors like AJAX handlers, REST API routes, shortcodes, or cron events is a significant strength, as it limits potential entry points for attackers. Furthermore, the code exclusively uses prepared statements for SQL queries and shows no critical or high-severity taint flows, indicating diligent handling of data and database interactions.
However, there are areas that warrant attention. The plugin has 50% of its output unescaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not properly sanitized before being displayed. The absence of nonce checks is a significant concern, as it leaves actions vulnerable to Cross-Site Request Forgery (CSRF) attacks. The plugin also performs a substantial number of file operations (30), which, while not inherently insecure, increases the potential for vulnerabilities if not handled with extreme care.
The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the limited attack surface and secure SQL handling, suggests a plugin that has been developed with security in mind. However, the lack of nonce checks and the unescaped output represent tangible risks that should be addressed to further harden the plugin's security profile.
Key Concerns
- Output escaping is only 50% proper
- No nonce checks present
hanapaena's Lite – Font & Style Manager – DSGVO/GDPR Security Vulnerabilities
hanapaena's Lite – Font & Style Manager – DSGVO/GDPR Release Timeline
hanapaena's Lite – Font & Style Manager – DSGVO/GDPR Code Analysis
Output Escaping
hanapaena's Lite – Font & Style Manager – DSGVO/GDPR Attack Surface
WordPress Hooks 6
Maintenance & Trust
hanapaena's Lite – Font & Style Manager – DSGVO/GDPR Maintenance & Trust
Maintenance Signals
Community Trust
hanapaena's Lite – Font & Style Manager – DSGVO/GDPR Alternatives
OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy.
host-webfonts-local
OMGF automagically caches the Google Fonts used by your theme/plugins locally. No configuration (or brains) required!
Disable and Remove Google Fonts | GDPR & DSGVO friendly
disable-remove-google-fonts
Improve frontend performance by disabling Google Fonts. GDPR and DSGVO friendly.
Self-Hosted Google Fonts
selfhost-google-fonts
Automatically self-host all the Google Fonts on your site. Plug and play.
Yabe Webfont – Use Custom Fonts, Google Fonts or Adobe Fonts
yabe-webfont
Easy self-host Google Fonts, Adobe Fonts support, or upload custom fonts in WordPress. Integrated into the most popular themes and page builders.
BunnyFonts for Divi
bunny-fonts-for-divi
Replaces Google Fonts with BunnyFonts to comply with GDPR regulations.
hanapaena's Lite – Font & Style Manager – DSGVO/GDPR Developer Profile
1 plugin · 90 total installs
How We Detect hanapaena's Lite – Font & Style Manager – DSGVO/GDPR
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pss-lfsmanager/admin/style/pss-plugin-admin.css/wp-content/plugins/pss-lfsmanager/admin/js/pss-lfsmanager-admin.js/wp-content/plugins/pss-lfsmanager/admin/js/pss-lfsmanager-admin.jspss-lfsmanager/admin/style/pss-plugin-admin.css?ver=pss-lfsmanager/admin/js/pss-lfsmanager-admin.js?ver=