Twentyfifteen Noto Sans JP Security & Risk Analysis

wordpress.org/plugins/twentyfifteen-noto-sans-jp

The font of TwentyFifteen is changed to a Japanese Gothic font.

60 active installs v0.2.1 PHP + WP 4.1+ Updated Feb 13, 2017
fontgoogle-fontsjapanesenoto-sanstwentyfifteen
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Twentyfifteen Noto Sans JP Safe to Use in 2026?

Generally Safe

Score 85/100

Twentyfifteen Noto Sans JP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "twentyfifteen-noto-sans-jp" plugin, in version 0.2.1, exhibits a generally positive security posture based on the provided static analysis. The absence of any reported CVEs and a complete lack of vulnerabilities in its history are strong indicators of a well-maintained and secure plugin. Furthermore, the static analysis reveals no dangerous functions, no direct SQL queries (all are prepared), no file operations, no external HTTP requests, and no observable attack surface through AJAX, REST API, shortcodes, or cron events. This suggests a minimal and well-contained functionality.

However, a significant concern arises from the output escaping. With 13% of outputs properly escaped, the vast majority of outputs are not, presenting a clear risk of Cross-Site Scripting (XSS) vulnerabilities. While taint analysis shows no current exploitable flows, this high percentage of unescaped output could easily become a vector for attack if any user-supplied data is processed and outputted without proper sanitization. The complete absence of nonce and capability checks, while not directly a risk given the zero attack surface, means that if the plugin were to evolve and introduce new entry points, these critical security mechanisms would be missing by default, requiring manual addition.

In conclusion, while the plugin is free from known vulnerabilities and has a minimal attack surface, the prevalent issue of unescaped output is a critical weakness that demands immediate attention. The lack of history regarding vulnerabilities is a strength, but the current code analysis highlights a significant risk that could be exploited. The absence of authorization checks, though currently benign, should be noted as a potential future risk if functionality expands.

Key Concerns

  • High percentage of unescaped output
Vulnerabilities
None known

Twentyfifteen Noto Sans JP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Twentyfifteen Noto Sans JP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

13% escaped8 total outputs
Attack Surface

Twentyfifteen Noto Sans JP Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionwp_enqueue_scripts2015-notosans-ja.php:137
actionplugins_loaded2015-notosans-ja.php:138
actioncustomize_registeradmin\customizer.php:49
actioncustomize_preview_initadmin\customizer.php:55
actiontiny_mce_before_initadmin\editor-style.php:21
actionadmin_initadmin\editor-style.php:59
Maintenance & Trust

Twentyfifteen Noto Sans JP Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedFeb 13, 2017
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

Twentyfifteen Noto Sans JP Developer Profile

John LeBlanc

8 plugins · 430 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Twentyfifteen Noto Sans JP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/twentyfifteen-noto-sans-jp/noto-sans-japanese.css/wp-content/plugins/twentyfifteen-noto-sans-jp/admin/js/customizer-preview.js
Script Paths
/wp-content/plugins/twentyfifteen-noto-sans-jp/admin/js/customizer-preview.js

HTML / DOM Fingerprints

HTML Comments
/* TwentyFifteen NotoSans JP Font Weight settings for TinyMCE */** https://wordpress.org/plugins/twentyfifteen-noto-sans-jp/ **
FAQ

Frequently Asked Questions about Twentyfifteen Noto Sans JP