
FontIran Font Changer Security & Risk Analysis
wordpress.org/plugins/fontiran-font-changerWebsite font change plugin
Is FontIran Font Changer Safe to Use in 2026?
Generally Safe
Score 85/100FontIran Font Changer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'fontiran-font-changer' v3 plugin exhibits several concerning security practices, despite a clean vulnerability history. The primary risk stems from its two AJAX handlers, both of which lack authentication checks. This creates a significant attack surface where unauthorized users could potentially trigger malicious actions. While the plugin uses prepared statements for SQL queries and has some nonce and capability checks, the absence of proper authorization for its AJAX endpoints is a critical oversight.
The taint analysis reveals flows with unsanitized paths, although these did not reach a critical or high severity in the static analysis. This suggests a potential for path traversal or other file manipulation vulnerabilities if these flows are combined with the unprotected AJAX endpoints. The low percentage of properly escaped output is another area of concern, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities.
While the plugin has no recorded vulnerabilities, this could be due to a lack of thorough auditing or that the existing weaknesses have not yet been exploited or discovered. The combination of an exposed attack surface and inadequate output escaping presents a notable security risk. The strengths lie in its use of prepared SQL statements and some (though insufficient) authentication checks. However, the unprotected AJAX handlers and poor output escaping are major weaknesses that need immediate attention.
Key Concerns
- AJAX handlers without authentication checks
- Low percentage of properly escaped output
- Flows with unsanitized paths
FontIran Font Changer Security Vulnerabilities
FontIran Font Changer Code Analysis
Output Escaping
Data Flow Analysis
FontIran Font Changer Attack Surface
AJAX Handlers 2
WordPress Hooks 7
Maintenance & Trust
FontIran Font Changer Maintenance & Trust
Maintenance Signals
Community Trust
FontIran Font Changer Alternatives
Dehkadeh Fonts
dehkadeh-fonts
This plugin help you to set persian fonts and size for different parts of the theme via wordpress customizer as easily. Also you can set the custom fo …
Easy Google Fonts
easy-google-fonts
Adds google fonts to any theme without coding and integrates with the WordPress Customizer automatically for a realtime live preview.
TypeSquare Webfonts for エックスサーバー
xserver-typesquare-webfonts
エックスサーバー株式会社が提供する各レンタルサーバーサービスでWebフォントを利用できるプラグインです。
TypeSquare Webfonts for ConoHa
ts-webfonts-for-conoha
ConoHa WINGで株式会社モリサワが提供するWebフォントサービス「TypeSquare」を利用できるプラグインです。
Icons Font Loader – Load Web Fonts and Icon Libraries
icons-font-loader
Load essential Flaticon webfonts into your WordPress site. Use icons anywhere on your site with simple integration, ensuring fast performance.
FontIran Font Changer Developer Profile
1 plugin · 200 total installs
How We Detect FontIran Font Changer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fontiran-font-changer/assets/css/admin.css/wp-content/plugins/fontiran-font-changer/assets/css/fi-fonts.css/wp-content/plugins/fontiran-font-changer/assets/css/colpick.css/wp-content/plugins/fontiran-font-changer/assets/js/colpick.min.js/wp-content/plugins/fontiran-font-changer/assets/js/admin.js/wp-content/plugins/fontiran-font-changer/assets/css/fi-main.css/wp-content/plugins/fontiran-font-changer/assets/js/colpick.min.js/wp-content/plugins/fontiran-font-changer/assets/js/admin.jsfiran-adminnfiran-fontsfiran-colpickfontiran-admin-jsfiran-fonts-mainHTML / DOM Fingerprints
fontiran-wrapfiran-dashboardfiran-uploadfiran-fontsdata-fontiranFontiran_Admin