TS Webfonts for さくらのレンタルサーバ Security & Risk Analysis

wordpress.org/plugins/ts-webfonts-for-sakura

さくらのレンタルサーバで株式会社モリサワ提供のWebフォント33書体が無料で利用できるプラグインです。

30K active installs v3.1.4 PHP + WP 5.2+ Updated Feb 14, 2024
font
84
B · Generally Safe
CVEs total3
Unpatched0
Last CVEJul 20, 2023
Safety Verdict

Is TS Webfonts for さくらのレンタルサーバ Safe to Use in 2026?

Mostly Safe

Score 84/100

TS Webfonts for さくらのレンタルサーバ is generally safe to use though it hasn't been updated recently. 3 past CVEs were resolved. Keep it updated.

3 known CVEsLast CVE: Jul 20, 2023Updated 2yr ago
Risk Assessment

The "ts-webfonts-for-sakura" plugin v3.1.4 exhibits a mixed security posture. While the static analysis shows a commendable lack of direct entry points like AJAX handlers, REST API routes, or shortcodes, and a good percentage of properly escaped output, there are notable concerns. Specifically, the presence of "flows with unsanitized paths" in the taint analysis, even without critical or high severity, suggests a potential for vulnerabilities if these paths are user-controllable. The plugin's history of three medium severity CVEs, all related to Cross-site Scripting and Cross-Site Request Forgery, is a significant red flag. The fact that these have been patched is positive, but the consistent occurrence of these vulnerability types indicates a recurring weakness in how user input is handled or protected against manipulation. Overall, the plugin has strengths in its limited attack surface and use of prepared statements, but the identified taint flows and historical vulnerability patterns warrant careful consideration and vigilance.

Key Concerns

  • 3 medium severity CVEs in vulnerability history
  • 3 flows with unsanitized paths
  • 13% of outputs not properly escaped
Vulnerabilities
3

TS Webfonts for さくらのレンタルサーバ Security Vulnerabilities

CVEs by Year

3 CVEs in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2023-32625medium · 4.3Cross-Site Request Forgery (CSRF)

TS Webfonts for SAKURA <= 3.1.2 - Cross-Site Request Forgery

Jul 20, 2023 Patched in 3.1.3 (187d)
CVE-2023-32624medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

TS Webfonts for SAKURA <= 3.1.0 - Authenticated (Admin+) Stored Cross-Site Scripting

Jul 20, 2023 Patched in 3.1.1 (187d)
CVE-2023-34169medium · 4.3Cross-Site Request Forgery (CSRF)

TS Webfonts for さくらのレンタルサーバ <= 3.1.1 - Cross-Site Request Forgery

May 31, 2023 Patched in 3.1.2 (237d)
Code Analysis
Analyzed Mar 16, 2026

TS Webfonts for さくらのレンタルサーバ Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
138 escaped
Nonce Checks
8
Capability Checks
3
File Operations
2
External Requests
2
Bundled Libraries
0

Output Escaping

87% escaped158 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

4 flows3 with unsanitized paths
<admin-root> (inc\admin-root.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

TS Webfonts for さくらのレンタルサーバ Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionwp_dashboard_setupinc\admin-dashboard.php:16
actionwp_enqueue_scriptsts-webfonts-for-sakura.php:44
actionwp_headts-webfonts-for-sakura.php:45
actionpre_get_poststs-webfonts-for-sakura.php:46
filtermce_buttonsts-webfonts-for-sakura.php:381
actionadmin_menutypesquare-admin.php:28
actionadmin_menutypesquare-admin.php:29
actionadmin_inittypesquare-admin.php:30
actionadmin_noticestypesquare-admin.php:31
actionadmin_noticestypesquare-admin.php:32
actionsave_posttypesquare-admin.php:33
actionadmin_enqueue_scriptstypesquare-admin.php:34
Maintenance & Trust

TS Webfonts for さくらのレンタルサーバ Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedFeb 14, 2024
PHP min version
Downloads372K

Community Trust

Rating54/100
Number of ratings3
Active installs30K
Developer Profile

TS Webfonts for さくらのレンタルサーバ Developer Profile

sakurainternet

3 plugins · 82K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
204 days
View full developer profile
Detection Fingerprints

How We Detect TS Webfonts for さくらのレンタルサーバ

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ts-webfonts-for-sakura/inc/css/typesquare.css/wp-content/plugins/ts-webfonts-for-sakura/inc/css/typesquare-editor.css
Script Paths
/wp-content/plugins/ts-webfonts-for-sakura/js/ts-webfonts-for-sakura.js
Version Parameters
ts-webfonts-for-sakura/js/ts-webfonts-for-sakura.js?ver=typesquare_std

HTML / DOM Fingerprints

CSS Classes
typesquare
HTML Comments
<!-- TS Webfonts for SAKURA RS -->
JS Globals
TypeSquare
FAQ

Frequently Asked Questions about TS Webfonts for さくらのレンタルサーバ