System Fonts Security & Risk Analysis

wordpress.org/plugins/system-fonts

Enqueues a stylesheet that lets you use the native font on each operating system.

40 active installs v0.6 PHP 5.6+ WP 4.6+ Updated Unknown
front-endtypography
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is System Fonts Safe to Use in 2026?

Generally Safe

Score 100/100

System Fonts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "system-fonts" plugin v0.6 exhibits an excellent security posture based on the provided static analysis. The absence of any identifiable attack surface points, such as AJAX handlers, REST API routes, shortcodes, or cron events, significantly reduces the potential for unauthorized access or manipulation. Furthermore, the code demonstrates robust security practices, with no dangerous functions, all SQL queries utilizing prepared statements, and all outputs being properly escaped. The lack of file operations, external HTTP requests, nonce checks, and capability checks, while contributing to a minimal attack surface, also indicates a very simple and likely non-interactive plugin functionality, which is generally a positive for security.

The taint analysis reveals no flows with unsanitized paths, and critically, no high or critical severity issues. This reinforces the static analysis findings that the code is clean and doesn't appear to introduce vulnerabilities related to data handling. The vulnerability history is also entirely clear, with no recorded CVEs of any severity. This indicates that the plugin has either never been a target for vulnerabilities or has maintained a high standard of security over its existence.

In conclusion, the "system-fonts" plugin v0.6 presents a very strong security profile. Its minimal attack surface, adherence to secure coding practices, and clean vulnerability history all contribute to a low-risk assessment. The lack of any identified security concerns in the static analysis and taint flows, coupled with a pristine vulnerability record, suggests this plugin is likely safe to use.

Vulnerabilities
None known

System Fonts Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

System Fonts Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

System Fonts Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioninitsystem-fonts.php:37
actionwp_enqueue_scriptssystem-fonts.php:41
Maintenance & Trust

System Fonts Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedUnknown
PHP min version5.6
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

System Fonts Developer Profile

Nilo Velez

4 plugins · 17K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect System Fonts

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/system-fonts/system-fonts.css/wp-content/plugins/system-fonts/system-fonts.min.css
Version Parameters
system-fonts/system-fonts.css?ver=system-fonts/system-fonts.min.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about System Fonts