Fonts to Uploads Security & Risk Analysis

wordpress.org/plugins/fonts-to-uploads

Relocate the WordPress fonts folder to the uploads directory.

20 active installs v1.0.1 PHP 7.4+ WP 6.4+ Updated Mar 21, 2024
font-libraryuploads
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Fonts to Uploads Safe to Use in 2026?

Generally Safe

Score 85/100

Fonts to Uploads has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "fonts-to-uploads" plugin v1.0.1 exhibits an exceptionally strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, nonce checks, or capability checks on its entry points suggests a deliberate effort to adhere to secure coding practices. The plugin's attack surface is effectively zero, and taint analysis reveals no vulnerabilities. This indicates that the plugin is likely very safe from common web vulnerabilities such as SQL injection, Cross-Site Scripting (XSS), and remote code execution through its current codebase.

The vulnerability history further reinforces this positive assessment, with no known CVEs ever recorded for this plugin. This pattern suggests a consistently secure development and maintenance approach. While the plugin demonstrates excellent strengths in code hygiene and a lack of historical issues, the complete absence of any identified security signals, including those that might typically be present even in well-coded plugins (like specific output escaping or capability checks on certain internal functions), is noteworthy. However, given the zero attack surface and the lack of any negative findings, this can be interpreted as a highly secure and well-contained plugin.

Vulnerabilities
None known

Fonts to Uploads Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Fonts to Uploads Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Fonts to Uploads Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filterfont_dirinc\namespace.php:17
actioninitinc\namespace.php:25
Maintenance & Trust

Fonts to Uploads Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMar 21, 2024
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Fonts to Uploads Developer Profile

Peter Wilson

5 plugins · 180 total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Fonts to Uploads

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
fonts-to-uploads/style.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Fonts to Uploads