Host Google Fonts Locally – Fast & Super Lightweight (30kb) by EasyFonts Security & Risk Analysis

wordpress.org/plugins/easyfonts

Locally host google font on your server for faster loading 🚀, and 💯 GDPR & DSGVO friendly fonts. Super lightweight plugin⚡, No server & cpu overload

1K active installs v1.2.0 PHP 5.6+ WP 5.0+ Updated Oct 5, 2025
fontsgdprgoogle-fontshost-google-fontstags-font
99
A · Safe
CVEs total1
Unpatched0
Last CVEApr 9, 2025
Safety Verdict

Is Host Google Fonts Locally – Fast & Super Lightweight (30kb) by EasyFonts Safe to Use in 2026?

Generally Safe

Score 99/100

Host Google Fonts Locally – Fast & Super Lightweight (30kb) by EasyFonts has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 9, 2025Updated 6mo ago
Risk Assessment

The "easyfonts" plugin v1.2.0 exhibits a mixed security posture. On the positive side, the static analysis reveals no identified critical or high-severity taint flows, no dangerous functions used, and SQL queries are consistently prepared. Furthermore, the plugin demonstrates some awareness of security by including a nonce check and a capability check, which are good practices. However, there are areas for improvement. The output escaping is only at 67%, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities if the unescaped outputs are user-controlled or rendered in sensitive contexts. The presence of file operations and external HTTP requests, while not inherently insecure, warrant careful review for any potential misconfigurations or vulnerabilities that could be exploited.

The vulnerability history, though showing no currently unpatched CVEs, highlights a past medium-severity Cross-Site Request Forgery (CSRF) vulnerability. This indicates that the plugin has had security flaws in the past, suggesting a need for ongoing vigilance and rigorous testing. While the current version seems to have addressed past issues, the history itself is a signal that the plugin's security track record is not entirely clean. Overall, "easyfonts" v1.2.0 has some commendable security features but has weaknesses in output escaping and a history of past vulnerabilities that warrant attention.

Key Concerns

  • Output escaping is not comprehensive
  • Past medium severity vulnerability recorded
Vulnerabilities
1

Host Google Fonts Locally – Fast & Super Lightweight (30kb) by EasyFonts Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-31005medium · 4.3Cross-Site Request Forgery (CSRF)

Easyfonts <= 1.1.2 - Cross-Site Request Forgery

Apr 9, 2025 Patched in 1.1.3 (7d)
Code Analysis
Analyzed Mar 16, 2026

Host Google Fonts Locally – Fast & Super Lightweight (30kb) by EasyFonts Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
10 escaped
Nonce Checks
1
Capability Checks
1
File Operations
7
External Requests
2
Bundled Libraries
0

Output Escaping

67% escaped15 total outputs
Attack Surface

Host Google Fonts Locally – Fast & Super Lightweight (30kb) by EasyFonts Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionplugins_loadedeasyfonts.php:34
actiontemplate_redirecteasyfonts.php:35
actionadmin_enqueue_scriptseasyfonts.php:36
filterwordpress_prepare_outputeasyfonts.php:63
filtergroovy_menu_final_outputeasyfonts.php:64
actionadmin_noticesinc\notices.php:18
actionadmin_menuinc\options.php:9
actionadmin_initinc\options.php:10
actionadmin_enqueue_scriptsinc\options.php:11
Maintenance & Trust

Host Google Fonts Locally – Fast & Super Lightweight (30kb) by EasyFonts Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 5, 2025
PHP min version5.6
Downloads9K

Community Trust

Rating100/100
Number of ratings6
Active installs1K
Developer Profile

Host Google Fonts Locally – Fast & Super Lightweight (30kb) by EasyFonts Developer Profile

Uzair

4 plugins · 2K total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Host Google Fonts Locally – Fast & Super Lightweight (30kb) by EasyFonts

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easyfonts/inc/options.css/wp-content/plugins/easyfonts/inc/notices.css
Script Paths
/wp-content/plugins/easyfonts/inc/options.js
Version Parameters
/wp-content/plugins/easyfonts/inc/options.css?ver=/wp-content/plugins/easyfonts/inc/notices.css?ver=/wp-content/plugins/easyfonts/inc/options.js?ver=

HTML / DOM Fingerprints

CSS Classes
easyfonts-optionseasyfonts-notice
JS Globals
easyfonts_ajax_object
FAQ

Frequently Asked Questions about Host Google Fonts Locally – Fast & Super Lightweight (30kb) by EasyFonts