
Japanese font for WordPress(Previously: Japanese Font for TinyMCE) Security & Risk Analysis
wordpress.org/plugins/japanese-font-for-tinymceAdd Japanese font to Gutenberg and TinyMCE Advanced plugin's font family selections.
Is Japanese font for WordPress(Previously: Japanese Font for TinyMCE) Safe to Use in 2026?
Generally Safe
Score 100/100Japanese font for WordPress(Previously: Japanese Font for TinyMCE) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the 'japanese-font-for-tinymce' plugin v4.30 reveals a generally strong security posture. The absence of exposed entry points such as AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the attack surface. Furthermore, the code exhibits good practices in several areas, including 100% use of prepared statements for SQL queries, the presence of nonce and capability checks on all identified code paths, and no file operations or external HTTP requests. This indicates a cautious approach to handling sensitive operations.
However, a minor concern is the output escaping. While 80% of outputs are properly escaped, 20% (2 out of 10) are not. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly echoed without sanitization. The plugin's vulnerability history is also a positive indicator, with zero recorded CVEs, suggesting a history of stable and secure code. The bundling of TinyMCE v4.30, while not explicitly flagged as an issue, is an older version and could be a potential area for future investigation regarding known vulnerabilities in that specific version of the bundled library.
In conclusion, the plugin demonstrates good security hygiene by minimizing its attack surface and implementing robust checks for critical operations. The primary area for improvement lies in ensuring 100% output escaping to mitigate any potential XSS risks. The lack of historical vulnerabilities is a strong positive sign, but vigilance regarding bundled library versions is always advisable.
Key Concerns
- 2 out of 10 outputs are not properly escaped
- Bundled TinyMCE v4.30 is an older version
Japanese font for WordPress(Previously: Japanese Font for TinyMCE) Security Vulnerabilities
Japanese font for WordPress(Previously: Japanese Font for TinyMCE) Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Japanese font for WordPress(Previously: Japanese Font for TinyMCE) Attack Surface
WordPress Hooks 22
Maintenance & Trust
Japanese font for WordPress(Previously: Japanese Font for TinyMCE) Maintenance & Trust
Maintenance Signals
Community Trust
Japanese font for WordPress(Previously: Japanese Font for TinyMCE) Alternatives
EditorFontsize
wp-editor-fontsize
Allows you to change a font size in a visual editor
Twentyfifteen Noto Sans JP
twentyfifteen-noto-sans-jp
The font of TwentyFifteen is changed to a Japanese Gothic font.
Custom Fonts – Host Your Fonts Locally
custom-fonts
Custom Fonts is a powerful WordPress plugin that allows you to upload your own custom fonts or choose from a vast collection of Google Fonts, all host …
OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy.
host-webfonts-local
OMGF automagically caches the Google Fonts used by your theme/plugins locally. No configuration (or brains) required!
Fonts Plugin | Use Google Fonts, Adobe Fonts or Upload Fonts
olympus-google-fonts
The easiest to customize fonts in WordPress. Optimized for Speed. 1000+ font choices. Supports Google Fonts, Adobe Fonts and Upload Fonts.
Japanese font for WordPress(Previously: Japanese Font for TinyMCE) Developer Profile
2 plugins · 10K total installs
How We Detect Japanese font for WordPress(Previously: Japanese Font for TinyMCE)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/japanese-font-for-tinymce/addfont.css/wp-content/plugins/japanese-font-for-tinymce/addfont_lite.cssjapanese-font-for-tinymce/addfont.css?ver=japanese-font-for-tinymce/addfont_lite.css?ver=