
Replace Google Fonts with Bunny Fonts Security & Risk Analysis
wordpress.org/plugins/replace-google-fonts-with-bunny-fontsReplace Google Fonts with Bunny Fonts in the HTML Markup of your WordPress site.
Is Replace Google Fonts with Bunny Fonts Safe to Use in 2026?
Generally Safe
Score 85/100Replace Google Fonts with Bunny Fonts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the "replace-google-fonts-with-bunny-fonts" plugin version 2.1.2 appears to be generally good, based on the provided static analysis. There are no identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits the potential attack surface. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests are positive indicators. The use of prepared statements for all SQL queries is also a strong security practice.
However, a critical concern arises from the output escaping results. With one total output and 0% properly escaped, this indicates a potential for Cross-Site Scripting (XSS) vulnerabilities. Any data displayed to users that is not properly escaped can be manipulated by attackers to inject malicious scripts. The lack of capability checks and nonce checks, while not immediately exploitable due to the limited attack surface, could become a weakness if new entry points are introduced in future versions without proper security considerations.
The vulnerability history being completely clear is a positive sign, suggesting a well-maintained and secure plugin to date. However, the lack of past vulnerabilities does not guarantee future security, especially in light of the identified output escaping issue. The plugin's strengths lie in its minimal attack surface and secure data handling for SQL. Its primary weakness is the insufficient output escaping, which poses a direct XSS risk.
Key Concerns
- Output is not properly escaped
- No capability checks on entry points
- No nonce checks on entry points
Replace Google Fonts with Bunny Fonts Security Vulnerabilities
Replace Google Fonts with Bunny Fonts Code Analysis
Output Escaping
Replace Google Fonts with Bunny Fonts Attack Surface
WordPress Hooks 8
Maintenance & Trust
Replace Google Fonts with Bunny Fonts Maintenance & Trust
Maintenance Signals
Community Trust
Replace Google Fonts with Bunny Fonts Alternatives
GF to BF
gf-to-bf
Replace Your Google Fonts with Bunny Fonts in the HTML Language of your WordPress site.
Remove Google Fonts – Disable, Block, or Replace with Bunny Fonts for GDPR Compliance
use-bunnyfont-host-google-fonts
Easily remove Google Fonts, disable Google Fonts loading, 👉🏻🗑️ or replace them with Bunny Fonts to boost privacy, speed, and GDPR compliance. 🔐
BunnyFonts for Divi
bunny-fonts-for-divi
Replaces Google Fonts with BunnyFonts to comply with GDPR regulations.
Better Search Replace
better-search-replace
A simple plugin to update URLs or other text in a database.
Enable Media Replace
enable-media-replace
Easily replace any attached image/file by simply uploading a new file in the Media Library edit view - a real time saver!
Replace Google Fonts with Bunny Fonts Developer Profile
2 plugins · 1K total installs
How We Detect Replace Google Fonts with Bunny Fonts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
fonts.googleapis.com/cssfonts.bunny.net/css<link rel="preconnect" href="https://fonts.gstatic.com" crossorigin><link href="https://fonts.gstatic.com" crossorigin rel="preconnect" />