
Use Any Font | Custom Font Uploader Security & Risk Analysis
wordpress.org/plugins/use-any-fontUpload custom fonts with custom font uploader. Auto converts to woff2 for better performance. Self-hosted, GDPR compliant, and easy custom font plugin
Is Use Any Font | Custom Font Uploader Safe to Use in 2026?
Generally Safe
Score 97/100Use Any Font | Custom Font Uploader has a strong security track record. Known vulnerabilities have been patched promptly.
The "use-any-font" plugin v6.3.14 presents a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and has a high percentage of properly escaped outputs. The absence of dangerous functions and bundled libraries is also a strength. However, a significant concern arises from the attack surface analysis, which reveals one AJAX handler without any authentication checks. This represents a direct entry point for potential exploitation.
Taint analysis indicates two flows with unsanitized paths, though thankfully, these did not escalate to critical or high severity issues. While the current version has no unpatched CVEs, the plugin's history of four medium-severity vulnerabilities, including Cross-site Scripting (XSS), Cross-Site Request Forgery (CSRF), and Missing Authorization, is a strong indicator of past security weaknesses. The recent nature of the last vulnerability (September 2024) suggests ongoing attention to security is required.
In conclusion, while the plugin has made strides in secure coding practices like prepared statements and output escaping, the presence of an unprotected AJAX endpoint and a history of past vulnerabilities necessitate caution. The potential for exploitation via the unprotected AJAX handler and the historical patterns of common web vulnerabilities suggest that ongoing vigilance and regular updates are crucial for maintaining security.
Key Concerns
- AJAX handler without authentication check
- Flows with unsanitized paths found
- History of 4 medium severity CVEs
Use Any Font | Custom Font Uploader Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Use Any Font <= 6.3.08 - Cross-Site Request Forgery
Use Any Font | Custom Font Uploader <= 6.2.7 - Cross-Site Scripting
Use Any Font <= 6.1.7 - Cross-Site Request Forgery to API Key Deactivation
Use Any Font <= 6.2.0 - Unauthenticated Arbitrary CSS Appending
Use Any Font | Custom Font Uploader Code Analysis
Output Escaping
Data Flow Analysis
Use Any Font | Custom Font Uploader Attack Surface
AJAX Handlers 1
WordPress Hooks 26
Maintenance & Trust
Use Any Font | Custom Font Uploader Maintenance & Trust
Maintenance Signals
Community Trust
Use Any Font | Custom Font Uploader Alternatives
Fontify
fontify
Upload and apply custom fonts (WOFF or WOFF2) to your entire WordPress site, including admin panel — without writing code.
SafeFonts
safefonts
Host custom fonts locally in WordPress with advanced security validation, block editor integration, and CSS variables support.
Custom Fonts – Host Your Fonts Locally
custom-fonts
Custom Fonts is a powerful WordPress plugin that allows you to upload your own custom fonts or choose from a vast collection of Google Fonts, all host …
Fonts Plugin | Use Google Fonts, Adobe Fonts or Upload Fonts
olympus-google-fonts
The easiest to customize fonts in WordPress. Optimized for Speed. 1000+ font choices. Supports Google Fonts, Adobe Fonts and Upload Fonts.
Easy Google Fonts
easy-google-fonts
Adds google fonts to any theme without coding and integrates with the WordPress Customizer automatically for a realtime live preview.
Use Any Font | Custom Font Uploader Developer Profile
5 plugins · 535K total installs
How We Detect Use Any Font | Custom Font Uploader
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/use-any-font/assets/css/uaf_admin.css/wp-content/plugins/use-any-font/assets/js/uaf_admin.js/wp-content/plugins/use-any-font/assets/js/uaf_admin.jsuse-any-font/assets/css/uaf_admin.css?ver=use-any-font/assets/js/uaf_admin.js?ver=HTML / DOM Fingerprints
uaf_main_contentuaf_upload_fileuaf_upload_button<!-- UAF Main Content --><!-- UAF Admin Tabs --><!-- UAF Interface --><!-- UAF API Key Settings -->+5 moredata-uaf-tabuaf_server_url