DSGVO Google Web Fonts GDPR Security & Risk Analysis

wordpress.org/plugins/dsgvo-google-web-fonts-gdpr

The Plugin scan yout Theme functions.php file if there any Google Font calls. If there any calls to the Google font serber, the plugin get the font ur …

30 active installs v1.1 PHP + WP + Updated Mar 23, 2019
dsgvogdprgoogle-fonts
55
C · Use Caution
CVEs total1
Unpatched1
Last CVEApr 7, 2026
Safety Verdict

Is DSGVO Google Web Fonts GDPR Safe to Use in 2026?

Use With Caution

Score 55/100

DSGVO Google Web Fonts GDPR has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Apr 7, 2026Updated 7yr ago
Risk Assessment

The "dsgvo-google-web-fonts-gdpr" plugin v1.1 exhibits several concerning security weaknesses. While it demonstrates good practices in its handling of SQL queries, the presence of two AJAX handlers without authentication checks significantly expands the attack surface and creates readily accessible entry points for malicious actors. The taint analysis revealing flows with unsanitized paths further exacerbates this issue, suggesting potential for unexpected behavior or exploitation if these paths are manipulated.

The plugin's vulnerability history is a major red flag, with a known critical CVE that remains unpatched. The previous critical vulnerability was related to unrestricted file uploads, which is a severe issue that could lead to code execution. The fact that a critical vulnerability is still present indicates a lack of ongoing security diligence and patching processes.

In conclusion, despite the plugin's positive use of prepared statements for SQL, the critical unpatched vulnerability, unprotected AJAX endpoints, and potential taint flow issues paint a picture of a high-risk plugin. The consistent pattern of critical vulnerabilities suggests a fundamental flaw in the plugin's development and maintenance, making it a significant security concern.

Key Concerns

  • Unpatched critical CVE
  • AJAX handlers without auth checks
  • Flows with unsanitized paths
  • Low output escaping coverage
  • No capability checks
Vulnerabilities
1 published

DSGVO Google Web Fonts GDPR Security Vulnerabilities

CVEs by Year

1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Critical
1

1 total CVE

CVE-2026-3535critical · 9.8Unrestricted Upload of File with Dangerous Type

DSGVO Google Web Fonts GDPR <= 1.1 - Unauthenticated Arbitrary File Upload via 'fonturl' Parameter

Apr 7, 2026Unpatched
Version History

DSGVO Google Web Fonts GDPR Release Timeline

v1.1Current1 CVE
v1.01 CVE
Code Analysis
Analyzed Apr 16, 2026

DSGVO Google Web Fonts GDPR Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
4 escaped
Nonce Checks
1
Capability Checks
0
File Operations
12
External Requests
2
Bundled Libraries
0

Output Escaping

24% escaped17 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

3 flows2 with unsanitized paths
DSGVOGWPdownloadGoogleFonts (dsgvo-google-web-fonts-gdpr.php:58)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

DSGVO Google Web Fonts GDPR Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_DSGVOGWPdownloadGoogleFontsdsgvo-google-web-fonts-gdpr.php:44
noprivwp_ajax_DSGVOGWPdownloadGoogleFontsdsgvo-google-web-fonts-gdpr.php:46
WordPress Hooks 5
actionadmin_menudsgvo-google-web-fonts-gdpr.php:38
actionadmin_enqueue_scriptsdsgvo-google-web-fonts-gdpr.php:40
actionwp_enqueue_scriptsdsgvo-google-web-fonts-gdpr.php:277
actionwp_enqueue_scriptsdsgvo-google-web-fonts-gdpr.php:279
actionadmin_enqueue_scriptsdsgvo-google-web-fonts-gdpr.php:283
Maintenance & Trust

DSGVO Google Web Fonts GDPR Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedMar 23, 2019
PHP min version
Downloads9K

Community Trust

Rating100/100
Number of ratings2
Active installs30
Developer Profile

DSGVO Google Web Fonts GDPR Developer Profile

mlfactory

8 plugins · 21K total installs

67
trust score
Avg Security Score
83/100
Avg Patch Time
318 days
View full developer profile
Detection Fingerprints

How We Detect DSGVO Google Web Fonts GDPR

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dsgvo-google-web-fonts-gdpr/core/assets/css/admin-style.css

HTML / DOM Fingerprints

CSS Classes
gfontsdnldsts
Data Attributes
content_url()
FAQ

Frequently Asked Questions about DSGVO Google Web Fonts GDPR