
GFontr, Google WebFont Security & Risk Analysis
wordpress.org/plugins/gfontrThis plugin provides an easy way to include fonts from Google WebFont API.
Is GFontr, Google WebFont Safe to Use in 2026?
Generally Safe
Score 85/100GFontr, Google WebFont has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The gfontr plugin v1.2 presents a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and has no recorded vulnerabilities or CVEs, suggesting a history of stable and secure development. Furthermore, the static analysis shows no identified critical or high severity taint flows, indicating that data is generally handled safely within the plugin's analyzed code paths.
However, several concerns warrant attention. The presence of the `create_function` dangerous function is a significant red flag, as it can be used to execute arbitrary PHP code and is often a target for attackers. Additionally, the fact that 100% of output is not properly escaped presents a serious cross-site scripting (XSS) risk. This means that if any user-supplied data is rendered on the frontend without proper sanitization, it could be exploited to inject malicious scripts. The absence of nonce checks on entry points, while the attack surface is currently reported as zero, could become a vulnerability if new entry points are introduced without proper security measures.
In conclusion, while the plugin benefits from a clean vulnerability history and secure SQL handling, the use of `create_function` and the complete lack of output escaping are critical weaknesses that significantly elevate its risk profile. The plugin needs immediate attention to address these specific coding flaws to mitigate potential security breaches.
Key Concerns
- 100% of output not properly escaped
- Presence of dangerous function: create_function
- No nonce checks on entry points
GFontr, Google WebFont Security Vulnerabilities
GFontr, Google WebFont Release Timeline
GFontr, Google WebFont Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
GFontr, Google WebFont Attack Surface
WordPress Hooks 5
Maintenance & Trust
GFontr, Google WebFont Maintenance & Trust
Maintenance Signals
Community Trust
GFontr, Google WebFont Alternatives
Easy Google Fonts
easy-google-fonts
Adds google fonts to any theme without coding and integrates with the WordPress Customizer automatically for a realtime live preview.
Google Web Fonts Customizer (GWFC)
google-web-fonts-customizer-gwfc
This plugin integrates WordPress Customizer with Google Web Fonts, to add and use google fonts to any themes, no coding needed.
Supreme Google Webfonts
supreme-google-webfonts
Description: Adds all Google Webfonts into your visual editor panel when creating posts or pages. Now you have access to almost 700 universal, cross- …
Ultimate Fonts
ultimate-fonts
Adds Google Fonts to your WordPress website without coding. Customize any element with support for live preview in the Customizer.
Google Webfonts For Woo Framework
google-fonts-for-woo-framework
Give the WooThemes framework access to the full range of current Google Webfonts.
GFontr, Google WebFont Developer Profile
3 plugins · 120 total installs
How We Detect GFontr, Google WebFont
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gfontr/gfontr-js.jshttp://ajax.googleapis.com/ajax/libs/webfont/1/webfont.js/wp-content/plugins/gfontr/gfontr-js.jsHTML / DOM Fingerprints
currentFonts