Live Font Preview for WooCommerce Security & Risk Analysis

wordpress.org/plugins/live-font-preview-for-woocommerce

Allow customers to preview and select fonts for custom engravings and text on WooCommerce products with a real-time live preview.

0 active installs v1.0 PHP 7.4+ WP 6.0+ Updated Feb 23, 2026
engravingfontsproduct-customizationtypographywoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Live Font Preview for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Live Font Preview for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin "live-font-preview-for-woocommerce" v1.0 exhibits a generally strong security posture based on the provided static analysis. The absence of any known CVEs in its history and a clean record of past vulnerabilities is highly positive, indicating a well-maintained and secure development process or a lack of prior significant issues. The code analysis reveals a very small attack surface, with no reported AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the code demonstrates good practices in several key areas: no dangerous functions are identified, all SQL queries use prepared statements, external HTTP requests are absent, and a high percentage of output is properly escaped. Nonce and capability checks are also present, further strengthening its defense.

However, a single flow with an unsanitized path identified in the taint analysis, even without a critical or high severity rating, warrants attention as it represents a potential weakness. While the static analysis reports no unprotected entry points and a negligible attack surface, this single taint flow indicates that there might be a specific path in the code that could potentially lead to an exploit if not handled correctly. The plugin's strengths lie in its robust input validation, secure database operations, and minimal external dependencies. The primary concern, albeit minor based on the severity reporting, is the identified unsanitized path, which requires further investigation to understand its exploitability.

Key Concerns

  • Flow with unsanitized path detected
Vulnerabilities
None known

Live Font Preview for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Live Font Preview for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
61 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

98% escaped62 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
process_settings_form (includes\class-admin.php:139)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Live Font Preview for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionadmin_menuincludes\class-admin.php:35
actionadmin_enqueue_scriptsincludes\class-admin.php:36
actionadmin_initincludes\class-admin.php:38
actionwoocommerce_before_add_to_cart_buttonincludes\class-live-font-preview-for-woocommerce.php:14
filterwoocommerce_add_cart_item_dataincludes\class-live-font-preview-for-woocommerce.php:15
filterwoocommerce_get_item_dataincludes\class-live-font-preview-for-woocommerce.php:16
actionwoocommerce_checkout_create_order_line_itemincludes\class-live-font-preview-for-woocommerce.php:17
actionwp_enqueue_scriptsincludes\class-live-font-preview-for-woocommerce.php:20
actionadmin_initincludes\class-settings.php:23
actionplugins_loadedlive-font-preview-for-woocommerce.php:58
actionbefore_woocommerce_initlive-font-preview-for-woocommerce.php:59
actionadmin_noticeslive-font-preview-for-woocommerce.php:110
Maintenance & Trust

Live Font Preview for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 23, 2026
PHP min version7.4
Downloads71

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Live Font Preview for WooCommerce Developer Profile

WPMajestic

2 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Live Font Preview for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/live-font-preview-for-woocommerce/assets/css/frontend.css/wp-content/plugins/live-font-preview-for-woocommerce/assets/js/frontend.js/wp-content/plugins/live-font-preview-for-woocommerce/assets/css/admin.css/wp-content/plugins/live-font-preview-for-woocommerce/assets/js/admin.js
Script Paths
/wp-content/plugins/live-font-preview-for-woocommerce/assets/js/frontend.js/wp-content/plugins/live-font-preview-for-woocommerce/assets/js/admin.js
Version Parameters
live-font-preview-for-woocommerce/assets/css/frontend.css?ver=live-font-preview-for-woocommerce/assets/js/frontend.js?ver=live-font-preview-for-woocommerce/assets/css/admin.css?ver=live-font-preview-for-woocommerce/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
live-font-preview-wrapperlive-font-preview-inputlive-font-preview-preview
Data Attributes
data-lfp-input-iddata-lfp-font-familydata-lfp-font-sizedata-lfp-font-colordata-lfp-font-weightdata-lfp-font-style
JS Globals
live_font_preview_admin_params
FAQ

Frequently Asked Questions about Live Font Preview for WooCommerce