Google Web Fonts Customizer (GWFC) Security & Risk Analysis

wordpress.org/plugins/google-web-fonts-customizer-gwfc

This plugin integrates WordPress Customizer with Google Web Fonts, to add and use google fonts to any themes, no coding needed.

1K active installs v1.0.2 PHP + WP 3.8+ Updated Jul 15, 2014
fontsgoogle-fonts-wordpressgoogle-webfontstheme-fontstheme-fonts-plugin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Google Web Fonts Customizer (GWFC) Safe to Use in 2026?

Generally Safe

Score 85/100

Google Web Fonts Customizer (GWFC) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The security posture of the "google-web-fonts-customizer-gwfc" v1.0.2 plugin appears to be quite strong based on the provided static analysis and vulnerability history. The absence of any identified dangerous functions, SQL queries that aren't prepared, file operations, external HTTP requests, or obvious attack vectors like AJAX handlers, REST API routes, shortcodes, or cron events with insufficient authentication is a significant positive. The taint analysis also shows no critical or high severity issues, indicating a lack of detectable data flow vulnerabilities.

However, a notable concern arises from the output escaping. With only 29% of the 14 identified outputs being properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is not properly escaped before being displayed on the frontend could be exploited by attackers. The lack of nonces and capability checks on potential (though currently non-existent) entry points is a general weakness that would become a problem if new entry points were added without these security measures.

The vulnerability history is exceptionally clean, with no recorded CVEs of any severity. This suggests a history of secure development practices or perhaps limited scrutiny. While this is generally a good sign, it does not negate the identified XSS risk. The plugin's strengths lie in its minimal attack surface and secure handling of data-related operations. Its primary weakness lies in its insufficient output sanitization, posing a direct XSS threat.

Key Concerns

  • Insufficient output escaping (XSS risk)
Vulnerabilities
None known

Google Web Fonts Customizer (GWFC) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Google Web Fonts Customizer (GWFC) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

29% escaped14 total outputs
Attack Surface

Google Web Fonts Customizer (GWFC) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actioncustomize_registercontrols.php:46
actionadmin_menugwfc.php:44
actioncustomize_controls_print_footer_scriptsgwfc.php:74
actioncustomize_controls_print_scriptsgwfc.php:75
actionwp_headgwfc.php:140
actioncustomize_preview_initoutput.php:30
actioncustomize_registerregister.php:170
Maintenance & Trust

Google Web Fonts Customizer (GWFC) Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedJul 15, 2014
PHP min version
Downloads44K

Community Trust

Rating92/100
Number of ratings11
Active installs1K
Developer Profile

Google Web Fonts Customizer (GWFC) Developer Profile

Chanif Al-Fath

1 plugin · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Google Web Fonts Customizer (GWFC)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/google-web-fonts-customizer-gwfc/gwfc.js/wp-content/plugins/google-web-fonts-customizer-gwfc/gwfc.css/wp-content/plugins/google-web-fonts-customizer-gwfc/gwfc-live.js
Script Paths
gwfc.jsgwfc-live.js

HTML / DOM Fingerprints

HTML Comments
GWFC.PHPTABLE OF CONTENTSSetup MenuInclude Controls, Options Register, Output+9 more
Data Attributes
id='gwfc-body-font-family'id='gwfc-body-style'id='gwfc-h1-font-family'id='gwfc-h1-style'id='gwfc-h2-font-family'id='gwfc-h2-style'+14 more
FAQ

Frequently Asked Questions about Google Web Fonts Customizer (GWFC)