Google Webfonts For Woo Framework Security & Risk Analysis

wordpress.org/plugins/google-fonts-for-woo-framework

Give the WooThemes framework access to the full range of current Google Webfonts.

300 active installs v1.6.4 PHP + WP 3.3+ Updated May 3, 2017
fontsgoogle-webfontstypographywoo-frameworkwoothemes
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Google Webfonts For Woo Framework Safe to Use in 2026?

Generally Safe

Score 85/100

Google Webfonts For Woo Framework has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "google-fonts-for-woo-framework" plugin, version 1.6.4, exhibits a strong security posture based on the provided static analysis. The absence of known CVEs and any recorded vulnerabilities in its history is a significant positive indicator. Furthermore, the plugin demonstrates good practices by not exposing attack surface through AJAX handlers, REST API routes, shortcodes, or cron events, and all identified entry points appear to be protected. The use of prepared statements for all SQL queries is excellent, and the presence of capability checks and file operations with limited scope suggests a controlled approach to resource interaction.

However, the static analysis does reveal a concerning area: output escaping. With only 4% of the 28 total outputs properly escaped, there is a high risk of Cross-Site Scripting (XSS) vulnerabilities. This means that user-supplied or dynamically generated content displayed on the frontend or within the WordPress admin area might not be sufficiently sanitized, potentially allowing malicious scripts to be injected and executed. The single external HTTP request, while not inherently problematic, warrants careful review to ensure it does not expose sensitive information or introduce supply chain risks.

In conclusion, the plugin benefits from a robust historical security record and a well-protected attack surface. The primary weakness lies in its insufficient output escaping, which represents a tangible risk of XSS vulnerabilities. Addressing the output escaping issue should be the highest priority to improve the overall security of this plugin.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Google Webfonts For Woo Framework Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Google Webfonts For Woo Framework Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
27
1 escaped
Nonce Checks
0
Capability Checks
1
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

4% escaped28 total outputs
Attack Surface

Google Webfonts For Woo Framework Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_headgoogle-webfonts-for-woo-framework-admin.php:76
actionadmin_menugoogle-webfonts-for-woo-framework-admin.php:79
actionadmin_initgoogle-webfonts-for-woo-framework-admin.php:82
actionadmin_noticesgoogle-webfonts-for-woo-framework-admin.php:85
filterwf_get_google_fontsgoogle-webfonts-for-woo-framework-base.php:38
actionwp_headgoogle-webfonts-for-woo-framework-base.php:39
actionplugins_loadedgoogle-webfonts-for-woo-framework.php:93
Maintenance & Trust

Google Webfonts For Woo Framework Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedMay 3, 2017
PHP min version
Downloads36K

Community Trust

Rating100/100
Number of ratings13
Active installs300
Developer Profile

Google Webfonts For Woo Framework Developer Profile

Jason Judge

6 plugins · 910 total installs

81
trust score
Avg Security Score
81/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Google Webfonts For Woo Framework

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/google-fonts-for-woo-framework/assets/css/google-fonts-for-woo-framework.css/wp-content/plugins/google-fonts-for-woo-framework/assets/js/google-fonts-for-woo-framework.js
Script Paths
/wp-content/plugins/google-fonts-for-woo-framework/assets/js/google-fonts-for-woo-framework.js
Version Parameters
google-fonts-for-woo-framework/assets/css/google-fonts-for-woo-framework.css?ver=google-fonts-for-woo-framework/assets/js/google-fonts-for-woo-framework.js?ver=

HTML / DOM Fingerprints

CSS Classes
gwfc_google_api_keygwfc_font_subsetgwfc_font_weightsgwfc_font_stylegwfc_custom_font_sizegwfc_font_colorgwfc_google_fonts_options
HTML Comments
<!-- Google Webfonts (for subsets: --><!-- Google Webfonts For Woo Framework Settings -->
Data Attributes
data-gwfc-font-subsetdata-gwfc-font-weightsdata-gwfc-font-styledata-gwfc-custom-font-sizedata-gwfc-font-color
JS Globals
gwfc_settings_data
FAQ

Frequently Asked Questions about Google Webfonts For Woo Framework