
OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. Security & Risk Analysis
wordpress.org/plugins/host-webfonts-localOMGF automagically caches the Google Fonts used by your theme/plugins locally. No configuration (or brains) required!
Is OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. Safe to Use in 2026?
Generally Safe
Score 96/100OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin 'host-webfonts-local' v6.1.4 exhibits a mixed security posture. On the positive side, the static analysis shows strong adherence to secure coding practices regarding SQL queries, with 100% using prepared statements. The presence of nonce and capability checks on all identified AJAX entry points is also a significant strength, indicating an effort to protect against common WordPress vulnerabilities. Furthermore, the taint analysis reported no critical or high severity flows, suggesting that direct data manipulation vulnerabilities are not immediately apparent in this version.
However, several concerns warrant attention. The vulnerability history reveals a significant number of past CVEs, with one critical and two high severity vulnerabilities reported. The common types of these past vulnerabilities, including Missing Authorization, Improper Access Control, and Path Traversal, are serious and often indicate fundamental flaws in how the plugin handles user input and accesses files. While there are currently no unpatched CVEs, the recurring nature of these vulnerability types in its history suggests a potential for similar issues to re-emerge if not addressed comprehensively. The fact that 75% of output is properly escaped, while good, still leaves room for potential cross-site scripting (XSS) vulnerabilities in the remaining 25% of outputs, especially if those outputs handle user-supplied data.
In conclusion, while the current version demonstrates improvements in direct code-level security for SQL and AJAX endpoints, the plugin's past vulnerability history, particularly concerning authorization and path traversal, presents a notable risk. The 25% of unescaped output is a minor concern but should be monitored. The plugin's strengths lie in its prepared SQL statements and authentication checks on entry points, but its historical pattern of critical security flaws necessitates cautious use and ongoing vigilance.
Key Concerns
- Historically significant number of critical/high CVEs
- Recurring past vulnerability types (Auth, Path Traversal)
- 25% of output not properly escaped
OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. <= 5.7.9 - Missing Authorization to Unauthenticated Directory Deletion and Cross-Site Scripting
OMGF <= 4.5.11 - Authenticated (Admin+) Arbitrary Folder Deletion via Path Traversal
OMGF <= 4.5.3 - Subscriber+ Arbitrary File/Folder Deletion
OMGF <= 4.5.3 - Unauthenticated Path Traversal in REST API
OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. Code Analysis
Output Escaping
OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. Attack Surface
AJAX Handlers 6
WordPress Hooks 95
Maintenance & Trust
OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. Maintenance & Trust
Maintenance Signals
Community Trust
OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. Alternatives
Disable and Remove Google Fonts | GDPR & DSGVO friendly
disable-remove-google-fonts
Improve frontend performance by disabling Google Fonts. GDPR and DSGVO friendly.
Self-Hosted Google Fonts
selfhost-google-fonts
Automatically self-host all the Google Fonts on your site. Plug and play.
Yabe Webfont – Use Custom Fonts, Google Fonts or Adobe Fonts
yabe-webfont
Easy self-host Google Fonts, Adobe Fonts support, or upload custom fonts in WordPress. Integrated into the most popular themes and page builders.
Local Google Fonts
local-google-fonts
Host your used Google fonts on your server and make your site more GDPR compliant 💯.
Embed Google Fonts
embed-google-fonts
Embed Google Fonts tries to automatically replace registered Google Fonts from themes and plugin with local versions, directly loaded from your own se …
OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. Developer Profile
3 plugins · 311K total installs
How We Detect OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy.
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/host-webfonts-local/assets/css/omgf-admin.css/wp-content/plugins/host-webfonts-local/assets/js/omgf-admin.js/wp-content/plugins/host-webfonts-local/assets/js/omgf-admin.jshost-webfonts-local/assets/css/omgf-admin.css?ver=host-webfonts-local/assets/js/omgf-admin.js?ver=HTML / DOM Fingerprints
<!-- OMGF: Optimized Google Fonts --><!-- OMGF: Stylesheets -->