
Cache Google Web Font Security & Risk Analysis
wordpress.org/plugins/cache-google-fontThis plugin will cache google web font to local files.
Is Cache Google Web Font Safe to Use in 2026?
Generally Safe
Score 85/100Cache Google Web Font has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The cache-google-font plugin v1.3 exhibits a mixed security posture. While the plugin's attack surface appears minimal with no identified AJAX handlers, REST API routes, shortcodes, or cron events, this also implies limited functionality and thus fewer opportunities for direct exploitation. The absence of known CVEs and historical vulnerabilities is a positive indicator, suggesting a generally stable and secure development history. However, significant concerns arise from the code analysis. The fact that 100% of the identified SQL queries utilize prepared statements is excellent. Conversely, a complete lack of output escaping (0% properly escaped) is a critical vulnerability, potentially leading to cross-site scripting (XSS) attacks if any user-controlled data is ever reflected in the output. The presence of file operations and external HTTP requests, while not inherently insecure, warrants careful review in conjunction with the lack of capability checks or nonces, as these could become vectors for further compromise if not handled with extreme caution. The absence of taint analysis results is neutral; it may mean no flows were found or the analysis tools were not comprehensive enough.
Key Concerns
- All output is unescaped, risking XSS attacks.
- No capability checks on potential sensitive operations.
- No nonce checks on potential sensitive operations.
Cache Google Web Font Security Vulnerabilities
Cache Google Web Font Code Analysis
Output Escaping
Cache Google Web Font Attack Surface
WordPress Hooks 4
Maintenance & Trust
Cache Google Web Font Maintenance & Trust
Maintenance Signals
Community Trust
Cache Google Web Font Alternatives
OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy.
host-webfonts-local
OMGF automagically caches the Google Fonts used by your theme/plugins locally. No configuration (or brains) required!
Disable Google Fonts
disable-google-fonts
Disable enqueuing of fonts from Google used by WordPress core, default themes, Gutenberg, and many more.
Swap Google Fonts Display: Improve Font Rendering & Performance
swap-google-font-display
Ensure text remains visible during webfont load, reduce FOUT, and improve performance for a smoother user experience.
Cache External Scripts
cache-external-scripts
Save the Google Analytics file (gtag.js / analytics.js) locally to be able to cache it for longer than 2 hours for a better PageSpeed score!
Supreme Google Webfonts
supreme-google-webfonts
Description: Adds all Google Webfonts into your visual editor panel when creating posts or pages. Now you have access to almost 700 universal, cross- …
Cache Google Web Font Developer Profile
2 plugins · 20 total installs
How We Detect Cache Google Web Font
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cache-google-font/font.css/wp-content/plugins/cache-google-font/font.ttf