ShayanWeb Admin FontChanger | افزونه‌ی تغییر فونت پیشخوان وردپرس شایان وب Security & Risk Analysis

wordpress.org/plugins/shayanweb-admin-fontchanger

The easiest way to change the WordPress admin font for Farsi websites is by using this lightweight plugin!

2K active installs v1.10 PHP 5.6+ WP 5.2+ Updated Sep 7, 2025
adminfontswp-admin
99
A · Safe
CVEs total1
Unpatched0
Last CVEMay 16, 2025
Safety Verdict

Is ShayanWeb Admin FontChanger | افزونه‌ی تغییر فونت پیشخوان وردپرس شایان وب Safe to Use in 2026?

Generally Safe

Score 99/100

ShayanWeb Admin FontChanger | افزونه‌ی تغییر فونت پیشخوان وردپرس شایان وب has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: May 16, 2025Updated 7mo ago
Risk Assessment

The shayanweb-admin-fontchanger plugin version 1.10 demonstrates a mixed security posture. On the positive side, it shows good practices in avoiding dangerous functions, utilizing prepared statements for all SQL queries, and performing file operations or external HTTP requests. The presence of nonce and capability checks on its entry points (the single AJAX handler) is also encouraging, suggesting an effort to protect against unauthorized access. However, a significant concern arises from the low percentage of properly escaped output (13%). This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the user interface, especially if user-supplied data is not handled carefully before display.

The vulnerability history reveals a past medium-severity vulnerability, specifically Cross-Site Request Forgery (CSRF). While this vulnerability is marked as patched, the existence of such a past issue, even if not critical, warrants attention. It suggests that the plugin's development may have had security gaps in the past, and continued vigilance is necessary. The absence of critical or high severity vulnerabilities in the history, and the clean taint analysis results, are positive indicators that recent development may have addressed some of these concerns. Overall, the plugin has strengths in its controlled entry points and SQL handling, but the lack of robust output escaping is a notable weakness that requires remediation.

Key Concerns

  • Low percentage of properly escaped output
  • Past medium severity vulnerability (CSRF)
Vulnerabilities
1

ShayanWeb Admin FontChanger | افزونه‌ی تغییر فونت پیشخوان وردپرس شایان وب Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-48114medium · 4.3Cross-Site Request Forgery (CSRF)

ShayanWeb Admin FontChanger <= 1.9.1 - Cross-Site Request Forgery

May 16, 2025 Patched in 1.10 (117d)
Version History

ShayanWeb Admin FontChanger | افزونه‌ی تغییر فونت پیشخوان وردپرس شایان وب Release Timeline

v1.10Current
v1.9.11 CVE
v1.91 CVE
v1.8.11 CVE
v1.81 CVE
v1.7.21 CVE
v1.7.11 CVE
v1.71 CVE
v1.61 CVE
v1.5.21 CVE
v1.51 CVE
v1.41 CVE
v1.31 CVE
v1.21 CVE
v1.11 CVE
Code Analysis
Analyzed Mar 16, 2026

ShayanWeb Admin FontChanger | افزونه‌ی تغییر فونت پیشخوان وردپرس شایان وب Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
2 escaped
Nonce Checks
3
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

13% escaped15 total outputs
Attack Surface

ShayanWeb Admin FontChanger | افزونه‌ی تغییر فونت پیشخوان وردپرس شایان وب Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_shayanweb_fontchanger_ajax_options_saveinc\options.php:424
WordPress Hooks 10
filtermce_cssinc\classic-editor.php:15
actionelementor/editor/before_enqueue_scriptsinc\elementor-editor.php:29
actionadmin_enqueue_scriptsinc\font-changer.php:24
actionwp_enqueue_scriptsinc\front-font.php:24
actionwp_enqueue_scriptsinc\front-wpadminbar.php:23
actionadmin_noticesinc\notices.php:18
actionadmin_initinc\notices.php:30
actionadmin_menuinc\options.php:121
actionadmin_enqueue_scriptsinc\options.php:395
actionlogin_enqueue_scriptsinc\wp-login.php:25
Maintenance & Trust

ShayanWeb Admin FontChanger | افزونه‌ی تغییر فونت پیشخوان وردپرس شایان وب Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 7, 2025
PHP min version5.6
Downloads27K

Community Trust

Rating100/100
Number of ratings11
Active installs2K
Developer Profile

ShayanWeb Admin FontChanger | افزونه‌ی تغییر فونت پیشخوان وردپرس شایان وب Developer Profile

Shayan Farhang Pazhooh

1 plugin · 2K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
117 days
View full developer profile
Detection Fingerprints

How We Detect ShayanWeb Admin FontChanger | افزونه‌ی تغییر فونت پیشخوان وردپرس شایان وب

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shayanweb-admin-fontchanger/css/shabnam.css/wp-content/plugins/shayanweb-admin-fontchanger/css/vazir.css/wp-content/plugins/shayanweb-admin-fontchanger/css/sahel.css/wp-content/plugins/shayanweb-admin-fontchanger/css/shayanweb-elementorfont.css/wp-content/plugins/shayanweb-admin-fontchanger/css/shwebfontchanger.css/wp-content/plugins/shayanweb-admin-fontchanger/css/front-font.css/wp-content/plugins/shayanweb-admin-fontchanger/css/front-wpadminbar.css
Version Parameters
shayanweb-admin-fontchanger/css/shabnam.css?ver=shayanweb-admin-fontchanger/css/vazir.css?ver=shayanweb-admin-fontchanger/css/sahel.css?ver=shayanweb-admin-fontchanger/css/shayanweb-elementorfont.css?ver=shayanweb-admin-fontchanger/css/shwebfontchanger.css?ver=shayanweb-admin-fontchanger/css/front-font.css?ver=shayanweb-admin-fontchanger/css/front-wpadminbar.css?ver=

HTML / DOM Fingerprints

CSS Classes
elementor-panel-heading-titleelementor-panelace_editordashiconsdashicons-before:before#wpadminbar .ab-icon#wpadminbar>#wp-toolbar>#wp-admin-bar-root-default .ab-icon
HTML Comments
<!-- Plugin By: ShayanWeb.com - Shayan Farhang Pazhooh -->
FAQ

Frequently Asked Questions about ShayanWeb Admin FontChanger | افزونه‌ی تغییر فونت پیشخوان وردپرس شایان وب