Adobe Fonts (formerly Typekit) for WordPress Security & Risk Analysis

wordpress.org/plugins/typekit-fonts-for-wordpress

Integrate the Adobe Fonts service into your WordPress website or blog to use a range of over 25,000 high-quality fonts.

10K active installs v1.10.1 PHP + WP 6.0+ Updated Jul 17, 2024
adobedesignfontfontstypekit
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Adobe Fonts (formerly Typekit) for WordPress Safe to Use in 2026?

Generally Safe

Score 92/100

Adobe Fonts (formerly Typekit) for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin 'typekit-fonts-for-wordpress' version 1.10.1 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any identified vulnerabilities, coupled with the lack of critical taint flows and the use of prepared statements for SQL queries, indicates good development practices. The plugin also demonstrates a conscious effort to secure its entry points, with a total of zero unprotected entry points reported across AJAX handlers, REST API routes, shortcodes, and cron events. The presence of nonce and capability checks further solidifies its defensive measures.

Despite the overwhelmingly positive indicators, the analysis does reveal a single external HTTP request. While not inherently a vulnerability, this represents a potential attack vector if the external service is compromised or if the request is not properly sanitized before being sent. The limited scope of the analysis (0 flows analyzed in taint analysis) means that deeper, more complex vulnerabilities might not have been detected. However, given the current data, the plugin appears to be a low-risk addition to a WordPress site.

Key Concerns

  • Single external HTTP request identified
Vulnerabilities
None known

Adobe Fonts (formerly Typekit) for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Adobe Fonts (formerly Typekit) for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
28 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

88% escaped32 total outputs
Attack Surface

Adobe Fonts (formerly Typekit) for WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menutypekit-admin.php:25
actioninittypekit.php:119
actionplugins_loadedtypekit.php:121
actionwp_headtypekit.php:123
Maintenance & Trust

Adobe Fonts (formerly Typekit) for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedJul 17, 2024
PHP min version
Downloads329K

Community Trust

Rating98/100
Number of ratings7
Active installs10K
Developer Profile

Adobe Fonts (formerly Typekit) for WordPress Developer Profile

Tectalic

5 plugins · 15K total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Adobe Fonts (formerly Typekit) for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/typekit-fonts-for-wordpress/typekit-fonts-for-wordpress.php/wp-content/plugins/typekit-fonts-for-wordpress/typekit-admin.php/wp-content/plugins/typekit-fonts-for-wordpress/typekit-fonts-for-wordpress.js
Script Paths
https://use.typekit.net/%s.js

HTML / DOM Fingerprints

CSS Classes
wf-loadingwf-inactive
JS Globals
Typekit
FAQ

Frequently Asked Questions about Adobe Fonts (formerly Typekit) for WordPress