Japanese font for WordPress(Previously: Japanese Font for TinyMCE) Security & Risk Analysis

wordpress.org/plugins/japanese-font-for-tinymce

Add Japanese font to Gutenberg and TinyMCE Advanced plugin's font family selections.

10K active installs v4.30 PHP + WP 5.1+ Updated Dec 4, 2025
fontfontsjapanesejapanesefonttinymce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Japanese font for WordPress(Previously: Japanese Font for TinyMCE) Safe to Use in 2026?

Generally Safe

Score 100/100

Japanese font for WordPress(Previously: Japanese Font for TinyMCE) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The static analysis of the 'japanese-font-for-tinymce' plugin v4.30 reveals a generally strong security posture. The absence of exposed entry points such as AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the attack surface. Furthermore, the code exhibits good practices in several areas, including 100% use of prepared statements for SQL queries, the presence of nonce and capability checks on all identified code paths, and no file operations or external HTTP requests. This indicates a cautious approach to handling sensitive operations.

However, a minor concern is the output escaping. While 80% of outputs are properly escaped, 20% (2 out of 10) are not. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly echoed without sanitization. The plugin's vulnerability history is also a positive indicator, with zero recorded CVEs, suggesting a history of stable and secure code. The bundling of TinyMCE v4.30, while not explicitly flagged as an issue, is an older version and could be a potential area for future investigation regarding known vulnerabilities in that specific version of the bundled library.

In conclusion, the plugin demonstrates good security hygiene by minimizing its attack surface and implementing robust checks for critical operations. The primary area for improvement lies in ensuring 100% output escaping to mitigate any potential XSS risks. The lack of historical vulnerabilities is a strong positive sign, but vigilance regarding bundled library versions is always advisable.

Key Concerns

  • 2 out of 10 outputs are not properly escaped
  • Bundled TinyMCE v4.30 is an older version
Vulnerabilities
None known

Japanese font for WordPress(Previously: Japanese Font for TinyMCE) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Japanese font for WordPress(Previously: Japanese Font for TinyMCE) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
8 escaped
Nonce Checks
5
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE4.30

Output Escaping

80% escaped10 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
tinyjpfont_options_page (settings.php:25)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Japanese font for WordPress(Previously: Japanese Font for TinyMCE) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 22
actionenqueue_block_assetsgutenjpfont\src\init.php:33
actionenqueue_block_editor_assetsgutenjpfont\src\init.php:64
actioninitjapanese-tinymce.php:88
actioninitjapanese-tinymce.php:89
filtertiny_mce_before_initjapanese-tinymce.php:105
filtertiny_mce_before_initjapanese-tinymce.php:106
filtertiny_mce_before_initjapanese-tinymce.php:107
filtermce_buttonsjapanese-tinymce.php:110
filtermce_buttonsjapanese-tinymce.php:111
actionadmin_print_footer_scriptsjapanese-tinymce.php:114
actionadmin_enqueue_scriptsjapanese-tinymce.php:127
actionadmin_noticesnotice.php:33
actionadmin_initnotice.php:35
actionadmin_initnotice.php:42
actionadmin_noticesnotice.php:59
actionadmin_initnotice.php:61
actionadmin_initnotice.php:68
actionadmin_noticesnotice.php:86
actionadmin_initnotice.php:94
actionadmin_noticesnotice.php:106
actionadmin_initnotice.php:114
actionadmin_menusettings.php:6
Maintenance & Trust

Japanese font for WordPress(Previously: Japanese Font for TinyMCE) Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 4, 2025
PHP min version
Downloads130K

Community Trust

Rating76/100
Number of ratings6
Active installs10K
Developer Profile

Japanese font for WordPress(Previously: Japanese Font for TinyMCE) Developer Profile

raspi0124

2 plugins · 10K total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Japanese font for WordPress(Previously: Japanese Font for TinyMCE)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/japanese-font-for-tinymce/addfont.css/wp-content/plugins/japanese-font-for-tinymce/addfont_lite.css
Version Parameters
japanese-font-for-tinymce/addfont.css?ver=japanese-font-for-tinymce/addfont_lite.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Japanese font for WordPress(Previously: Japanese Font for TinyMCE)