
Persian Admnin Fonts Security & Risk Analysis
wordpress.org/plugins/persian-admin-fontsتغییر فونت های ادمین سایت شما با یک کلیک! به همراه 10 فونت معروف و استاندارد برای وب و قابلیت آپلود فونت های شخصی شما!
Is Persian Admnin Fonts Safe to Use in 2026?
Generally Safe
Score 99/100Persian Admnin Fonts has a strong security track record. Known vulnerabilities have been patched promptly.
The 'persian-admin-fonts' plugin v4.1.05 exhibits a mixed security posture. On the positive side, the static analysis indicates a relatively contained attack surface with all AJAX handlers protected by authentication checks. Furthermore, there are no raw SQL queries or unsanitized paths identified in the taint analysis, which are common sources of critical vulnerabilities.
However, several areas raise concerns. A significant portion of output (44%) is not properly escaped, potentially exposing the site to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled rigorously. The absence of nonce checks on the AJAX handlers, despite having capability checks, is a notable weakness that could be exploited if the capability checks themselves can be bypassed. While there are no currently unpatched CVEs, the plugin has a history of one known CVE, which was for a 'Missing Authorization' issue. This historical pattern, combined with the lack of specific nonce checks on AJAX endpoints, suggests a potential for authorization-related vulnerabilities in the future if not diligently addressed.
In conclusion, while the plugin has implemented some good security practices like prepared statements and authorization checks on its entry points, the unescaped output and the absence of nonce checks on AJAX endpoints represent tangible risks. The past CVE for missing authorization warrants vigilance. The plugin is not inherently insecure but requires careful monitoring and potential remediation of the identified output escaping and nonce check issues.
Key Concerns
- Significant portion of output not properly escaped
- No nonce checks on AJAX handlers
- Vulnerability history: 1 CVE (Missing Authorization)
Persian Admnin Fonts Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Persian Admnin Fonts <= 4.1.03 - Missing Authorization
Persian Admnin Fonts Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Persian Admnin Fonts Attack Surface
AJAX Handlers 4
WordPress Hooks 16
Maintenance & Trust
Persian Admnin Fonts Maintenance & Trust
Maintenance Signals
Community Trust
Persian Admnin Fonts Alternatives
No alternatives data available yet.
Persian Admnin Fonts Developer Profile
4 plugins · 730 total installs
How We Detect Persian Admnin Fonts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/persian-admin-fonts/libs/fonts/css/dynamicAdminFont.css/wp-content/plugins/persian-admin-fonts/libs/fonts/css/dynamic-front-fonts.csspersian-admin-fonts/style.css?ver=persian-admin-fonts/admin/css/pfmdz-admincss.css?ver=HTML / DOM Fingerprints
pfmdz-settings-pagedata-pfmdz-font-selectorpfmdz_admin_ajax_urlpfmdz_admin_nonce