FontX فونت فارسی Security & Risk Analysis

wordpress.org/plugins/fontx-persian-fonts

فونت فارسی ( فونت ایکس ) قابل استفاده در تمامی نسخه های وردپرس، ساده، کم حجم و سریع فونت های دلخواه خود را اعمال کنید .

100 active installs v1.1.0 PHP + WP 5.0+ Updated Nov 26, 2025
fontpersianrtl%d9%81%d9%88%d9%86%d8%aa%d9%81%d9%88%d9%86%d8%aa-%d9%81%d8%a7%d8%b1%d8%b3%db%8c
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FontX فونت فارسی Safe to Use in 2026?

Generally Safe

Score 100/100

FontX فونت فارسی has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "fontx-persian-fonts" v1.1.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of any reported CVEs, critical or high severity taint flows, and the use of prepared statements for all SQL queries are significant strengths. Furthermore, the plugin demonstrates good security practices by including nonce and capability checks, and importantly, it has no identified attack surface through AJAX, REST API, or shortcodes that lack authorization. The limited number of output instances and the 46% proper escaping suggest an area for improvement, as there's a potential for XSS if the unescaped outputs are rendered in a sensitive context. However, given the overall lack of attack vectors and sanitization issues, the immediate risk appears very low. The plugin's history of zero vulnerabilities further reinforces its current security, indicating a development team that prioritizes security or has been fortunate in avoiding significant issues. While the output escaping could be improved, the plugin is in a generally secure state.

Key Concerns

  • Output escaping is not consistently applied
Vulnerabilities
None known

FontX فونت فارسی Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

FontX فونت فارسی Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
6 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

46% escaped13 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
fontx_settings_page_callback (admin\settings-page.php:4)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

FontX فونت فارسی Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menufontx-persian-fonts.php:19
actionadmin_enqueue_scriptsfontx-persian-fonts.php:20
actionwp_enqueue_scriptsfontx-persian-fonts.php:21
Maintenance & Trust

FontX فونت فارسی Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 26, 2025
PHP min version
Downloads927

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

FontX فونت فارسی Developer Profile

RezaEi .Ali

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect FontX فونت فارسی

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fontx-persian-fonts/assets/admin-style.css

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about FontX فونت فارسی