
Google Web Fonts Customizer (GWFC) Security & Risk Analysis
wordpress.org/plugins/google-web-fonts-customizer-gwfcThis plugin integrates WordPress Customizer with Google Web Fonts, to add and use google fonts to any themes, no coding needed.
Is Google Web Fonts Customizer (GWFC) Safe to Use in 2026?
Generally Safe
Score 85/100Google Web Fonts Customizer (GWFC) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the "google-web-fonts-customizer-gwfc" v1.0.2 plugin appears to be quite strong based on the provided static analysis and vulnerability history. The absence of any identified dangerous functions, SQL queries that aren't prepared, file operations, external HTTP requests, or obvious attack vectors like AJAX handlers, REST API routes, shortcodes, or cron events with insufficient authentication is a significant positive. The taint analysis also shows no critical or high severity issues, indicating a lack of detectable data flow vulnerabilities.
However, a notable concern arises from the output escaping. With only 29% of the 14 identified outputs being properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is not properly escaped before being displayed on the frontend could be exploited by attackers. The lack of nonces and capability checks on potential (though currently non-existent) entry points is a general weakness that would become a problem if new entry points were added without these security measures.
The vulnerability history is exceptionally clean, with no recorded CVEs of any severity. This suggests a history of secure development practices or perhaps limited scrutiny. While this is generally a good sign, it does not negate the identified XSS risk. The plugin's strengths lie in its minimal attack surface and secure handling of data-related operations. Its primary weakness lies in its insufficient output sanitization, posing a direct XSS threat.
Key Concerns
- Insufficient output escaping (XSS risk)
Google Web Fonts Customizer (GWFC) Security Vulnerabilities
Google Web Fonts Customizer (GWFC) Code Analysis
Output Escaping
Google Web Fonts Customizer (GWFC) Attack Surface
WordPress Hooks 7
Maintenance & Trust
Google Web Fonts Customizer (GWFC) Maintenance & Trust
Maintenance Signals
Community Trust
Google Web Fonts Customizer (GWFC) Alternatives
Easy Google Fonts
easy-google-fonts
Adds google fonts to any theme without coding and integrates with the WordPress Customizer automatically for a realtime live preview.
Ultimate Fonts
ultimate-fonts
Adds Google Fonts to your WordPress website without coding. Customize any element with support for live preview in the Customizer.
Supreme Google Webfonts
supreme-google-webfonts
Description: Adds all Google Webfonts into your visual editor panel when creating posts or pages. Now you have access to almost 700 universal, cross- …
Google Webfonts For Woo Framework
google-fonts-for-woo-framework
Give the WooThemes framework access to the full range of current Google Webfonts.
Google Font
fonts-add
Google font for your website without coding, you can change font for any element you want.
Google Web Fonts Customizer (GWFC) Developer Profile
1 plugin · 1K total installs
How We Detect Google Web Fonts Customizer (GWFC)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/google-web-fonts-customizer-gwfc/gwfc.js/wp-content/plugins/google-web-fonts-customizer-gwfc/gwfc.css/wp-content/plugins/google-web-fonts-customizer-gwfc/gwfc-live.jsgwfc.jsgwfc-live.jsHTML / DOM Fingerprints
GWFC.PHPTABLE OF CONTENTSSetup MenuInclude Controls, Options Register, Output+9 moreid='gwfc-body-font-family'id='gwfc-body-style'id='gwfc-h1-font-family'id='gwfc-h1-style'id='gwfc-h2-font-family'id='gwfc-h2-style'+14 more