Inline Typography Controls Security & Risk Analysis

wordpress.org/plugins/inline-typography-controls

Add inline typography controls to the editor.

40 active installs v0.4.6 PHP 8.1+ WP 6.7+ Updated Feb 20, 2025
scheduleterm
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Inline Typography Controls Safe to Use in 2026?

Generally Safe

Score 92/100

Inline Typography Controls has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The static analysis of the "inline-typography-controls" plugin version 0.4.6 reveals a generally positive security posture. There are no identified dangerous functions, all SQL queries utilize prepared statements, and all outputs are properly escaped. Furthermore, the plugin has no history of known vulnerabilities, indicating a consistent track record of security. The absence of file operations and external HTTP requests also reduces potential attack vectors.

However, a significant concern arises from the complete lack of nonce checks and capability checks across all entry points. While the current attack surface is zero and all entry points appear to be unprotected, this indicates a potential for vulnerabilities to be introduced in future updates if new entry points are added without proper security measures. The taint analysis also shows no flows, which is positive, but this is in conjunction with an attack surface of zero, meaning no user-controlled data is being processed, which might not be representative of real-world usage.

In conclusion, the plugin exhibits good coding practices in its current version regarding SQL and output sanitization. The absence of past vulnerabilities is a strong indicator of developer diligence. The primary weakness lies in the lack of built-in security checks like nonces and capability checks, which, while not exploitable in the current zero-attack-surface state, represent a significant risk if the plugin's functionality or interaction points expand.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Inline Typography Controls Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Inline Typography Controls Release Timeline

v0.4.6Current
Code Analysis
Analyzed Mar 16, 2026

Inline Typography Controls Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Inline Typography Controls Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionenqueue_block_editor_assetsinline-typography-controls.php:18
actionenqueue_block_assetsinline-typography-controls.php:40
Maintenance & Trust

Inline Typography Controls Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 20, 2025
PHP min version8.1
Downloads595

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Inline Typography Controls Developer Profile

Toro_Unit (Hiroshi Urabe)

23 plugins · 216K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Inline Typography Controls

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/inline-typography-controls/build/index.css/wp-content/plugins/inline-typography-controls/build/index.js/wp-content/plugins/inline-typography-controls/build/style-index.css
Script Paths
/wp-content/plugins/inline-typography-controls/build/index.js
Version Parameters
inline-typography-controls/build/index.css?ver=inline-typography-controls/build/index.js?ver=inline-typography-controls/build/style-index.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Inline Typography Controls