
MW Font Changer Security & Risk Analysis
wordpress.org/plugins/parsi-fontChange your WordPress dashboard and theme font easy and fast :)
Is MW Font Changer Safe to Use in 2026?
Generally Safe
Score 85/100MW Font Changer has a strong security track record. Known vulnerabilities have been patched promptly.
The 'parsi-font' v5.3.1 plugin exhibits a mixed security posture. While the static analysis indicates a very small attack surface with no identifiable entry points that are unprotected, and all SQL queries are properly prepared, there are significant concerns regarding output escaping. A mere 5% of outputs are properly escaped, suggesting a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks on potential (though currently unlisted) entry points, combined with the low output escaping rate, presents a considerable risk.
The vulnerability history, while dated, is also noteworthy. The presence of a past medium-severity XSS vulnerability in 2016, along with the general pattern of XSS as a common vulnerability type for this plugin, reinforces the findings from the static analysis. This historical data, correlated with the current low output escaping rate, strongly suggests that the plugin may still be susceptible to XSS attacks. The plugin's current lack of unpatched vulnerabilities is a positive sign, but the fundamental code quality regarding output sanitization remains a significant weakness.
In conclusion, 'parsi-font' v5.3.1 has strengths in its limited attack surface and SQL practices. However, the extremely poor output escaping, coupled with historical XSS vulnerabilities, creates a substantial risk for XSS. Developers should prioritize addressing the output sanitization issues to mitigate these risks.
Key Concerns
- Poor output escaping (95% unescaped)
- Historical medium XSS vulnerability
- No capability checks found
- No nonce checks found
MW Font Changer Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
MW Font Changer <= 4.2.5 - Reflected Cross-Site Scripting
MW Font Changer Release Timeline
MW Font Changer Code Analysis
Output Escaping
MW Font Changer Attack Surface
WordPress Hooks 10
Maintenance & Trust
MW Font Changer Maintenance & Trust
Maintenance Signals
Community Trust
MW Font Changer Alternatives
Mandegar Feed
mandegar-feed
Show valuable posts of Mandegarweb in your dashboard
ShayanWeb Admin FontChanger | افزونهی تغییر فونت پیشخوان وردپرس شایان وب
shayanweb-admin-fontchanger
The easiest way to change the WordPress admin font for Farsi websites is by using this lightweight plugin!
Admin Custom Font
admin-custom-font
Admin Custom Font plugin allows you to replace default/factory font in WordPress Admin Dashboard with hundreds of different Google Fonts.
Font Size
font-size
Font Size is easy to use. Font Size WordPress plugin allows you to change the size of basic HTML elements.
Persian Admnin Fonts
persian-admin-fonts
تغییر فونت های ادمین سایت شما با یک کلیک! به همراه 10 فونت معروف و استاندارد برای وب و قابلیت آپلود فونت های شخصی شما!
MW Font Changer Developer Profile
2 plugins · 9K total installs
How We Detect MW Font Changer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/parsi-font/assets/css/fonts.css/wp-content/plugins/parsi-font/assets/css/admin.css/wp-content/plugins/parsi-font/assets/css/admin-rtl.cssHTML / DOM Fingerprints
mwfc-pro-version-noticeid="mwfc-pro-version-notice"