
Dyslexic Fonts Security & Risk Analysis
wordpress.org/plugins/dyslexic-fontsAllow users to change the font used across your site to one that is meant to help people with reading difficulties.
Is Dyslexic Fonts Safe to Use in 2026?
Generally Safe
Score 85/100Dyslexic Fonts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "dyslexic-fonts" plugin v0.18 exhibits a generally strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the attack surface. Furthermore, the code signals indicate a positive approach to security with no dangerous functions, 100% prepared SQL statements, and the presence of nonce and capability checks. The lack of known CVEs and historical vulnerabilities also suggests a well-maintained or less targeted plugin.
However, a critical concern arises from the output escaping analysis. With 100% of identified outputs not properly escaped, this plugin presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic content generated by the plugin and displayed to users could be exploited by attackers to inject malicious scripts. While the attack surface is small and other security practices are sound, this single oversight in output escaping creates a notable weakness that requires immediate attention.
In conclusion, the "dyslexic-fonts" plugin v0.18 has strong foundational security practices, particularly regarding input handling and access control. The lack of historical vulnerabilities is a positive indicator. Nevertheless, the complete lack of output escaping for all identified outputs is a severe flaw that overshadows the other strengths and poses a significant risk of XSS attacks.
Key Concerns
- 100% of outputs not properly escaped
Dyslexic Fonts Security Vulnerabilities
Dyslexic Fonts Release Timeline
Dyslexic Fonts Code Analysis
Output Escaping
Dyslexic Fonts Attack Surface
WordPress Hooks 6
Maintenance & Trust
Dyslexic Fonts Maintenance & Trust
Maintenance Signals
Community Trust
Dyslexic Fonts Alternatives
Custom Fonts – Host Your Fonts Locally
custom-fonts
Custom Fonts is a powerful WordPress plugin that allows you to upload your own custom fonts or choose from a vast collection of Google Fonts, all host …
Fonts Plugin | Google Fonts, Adobe Fonts & Upload Fonts
olympus-google-fonts
Instantly change your entire website's typography with Google Fonts, Adobe Fonts, or custom fonts — no coding required. Live preview your changes.
Use Any Font | Custom Font Uploader
use-any-font
Upload custom fonts with custom font uploader. Auto converts to woff2 for better performance. Self-hosted, GDPR compliant, and easy custom font plugin
Custom Adobe Fonts (Typekit)
custom-typekit-fonts
Custom Adobe Fonts allows you to extends the fonts supports from the Abobe Fonts.
Fonts
fonts
Add More Font To Your WordPress Editor
Dyslexic Fonts Developer Profile
11 plugins · 290 total installs
How We Detect Dyslexic Fonts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dyslexic-fonts/style.cssHTML / DOM Fingerprints
id="personalisation"id="dyslexic-font"name="_more_readable"<div id="personalisation"><h3>Site Personalisation</h3><table class="form-table"><tbody><tr title="If you have reading difficulties, enable this to use a different font across the site.">