TypeFlow Font Loader for Google Fonts Security & Risk Analysis

wordpress.org/plugins/typeflow-font-loader-google-fonts

Beautiful Google Fonts for WordPress with self-hosted GDPR-compliant mode — no coding required.

0 active installs v1.0.0 PHP 7.4+ WP 5.0+ Updated Mar 15, 2026
fontsgdprgoogle-fontsself-hostedtypography
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is TypeFlow Font Loader for Google Fonts Safe to Use in 2026?

Generally Safe

Score 100/100

TypeFlow Font Loader for Google Fonts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The 'typeflow-font-loader-google-fonts' v1.0.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good coding practices by utilizing prepared statements for all SQL queries and ensuring 100% of its outputs are properly escaped. It also correctly implements nonce and capability checks for its entry points and has no recorded vulnerability history, suggesting a generally secure development approach.

However, a significant concern arises from its attack surface. The plugin exposes one AJAX handler that lacks any authentication checks. This unprotected endpoint represents a direct pathway for attackers to interact with the plugin's functionality without proper authorization. While taint analysis did not reveal any critical or high-severity unsanitized flows, the absence of authentication on an AJAX handler is a critical oversight that could potentially be leveraged in conjunction with other weaknesses or vulnerabilities if they were to emerge.

In conclusion, while the plugin adheres to several security best practices like output escaping and prepared statements, the presence of an unprotected AJAX endpoint introduces a notable security risk. The absence of past vulnerabilities is a positive sign, but it does not negate the immediate risk posed by the unauthenticated entry point. Addressing this unprotected AJAX handler should be the highest priority for improving the plugin's security.

Key Concerns

  • Unprotected AJAX handler
Vulnerabilities
None known

TypeFlow Font Loader for Google Fonts Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

TypeFlow Font Loader for Google Fonts Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

TypeFlow Font Loader for Google Fonts Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
49 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped49 total outputs
Attack Surface
1 unprotected

TypeFlow Font Loader for Google Fonts Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_fp_gf_regenerate_fontsincludes/class-fp-gf-core.php:76
WordPress Hooks 9
actionplugins_loadedincludes/class-fp-gf-core.php:44
actioncustomize_registerincludes/class-fp-gf-core.php:51
actioncustomize_save_afterincludes/class-fp-gf-core.php:54
actionwp_enqueue_scriptsincludes/class-fp-gf-core.php:57
actionwp_enqueue_scriptsincludes/class-fp-gf-core.php:60
filterwp_resource_hintsincludes/class-fp-gf-core.php:63
actionadmin_enqueue_scriptsincludes/class-fp-gf-core.php:69
actionadmin_enqueue_scriptsincludes/class-fp-gf-core.php:70
actionadmin_menuincludes/class-fp-gf-core.php:73
Maintenance & Trust

TypeFlow Font Loader for Google Fonts Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 15, 2026
PHP min version7.4
Downloads257

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

TypeFlow Font Loader for Google Fonts Developer Profile

sebastianhornoi

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TypeFlow Font Loader for Google Fonts

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/typeflow-font-loader-google-fonts/admin/css/fontpress-admin.css/wp-content/plugins/typeflow-font-loader-google-fonts/admin/js/fontpress-admin.js
Script Paths
/wp-content/plugins/typeflow-font-loader-google-fonts/admin/js/fontpress-admin.js
Version Parameters
typeflow-font-loader-google-fonts/admin/css/fontpress-admin.css?ver=typeflow-font-loader-google-fonts/admin/js/fontpress-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
gfl-regenerate-fontsgfl-regenerate-message
Data Attributes
data-section="gfl_section"
JS Globals
typeflowAdmin
FAQ

Frequently Asked Questions about TypeFlow Font Loader for Google Fonts