Use Bangla Fonts Security & Risk Analysis

wordpress.org/plugins/use-bangla-fonts

Use Bangla Fonts .

10 active installs v2.0.0 PHP + WP 6.0+ Updated Jul 27, 2025
bangla-fontbangla-font-for-wordpressbangla-font-gutenberggutenberggutenberg-tools
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Use Bangla Fonts Safe to Use in 2026?

Generally Safe

Score 100/100

Use Bangla Fonts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The "use-bangla-fonts" plugin version 2.0.0 demonstrates a generally positive security posture with several strengths. It has no known CVEs, indicating a history of responsible development or a lack of significant past vulnerabilities. The code analysis reveals no dangerous functions or SQL queries executed without prepared statements, which are excellent practices. Furthermore, the plugin has a limited attack surface with only two AJAX entry points, and importantly, these appear to have authorization checks, along with a nonce check and a capability check in place. There are also no external HTTP requests or bundled libraries, reducing potential attack vectors.

However, a notable concern lies in the output escaping. With only 37% of outputs properly escaped, there is a significant risk of cross-site scripting (XSS) vulnerabilities. If user-supplied data is not sufficiently sanitized before being displayed on the frontend, an attacker could inject malicious scripts. While the plugin has a clean vulnerability history and no critical or high-severity taint flows were detected in this analysis, the unescaped output presents a tangible risk that needs to be addressed. The lack of shortcodes, cron events, and REST API routes is a positive for attack surface reduction.

Key Concerns

  • Low output escaping percentage
Vulnerabilities
None known

Use Bangla Fonts Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Use Bangla Fonts Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
7 escaped
Nonce Checks
1
Capability Checks
1
File Operations
4
External Requests
0
Bundled Libraries
0

Output Escaping

37% escaped19 total outputs
Attack Surface

Use Bangla Fonts Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_delete_custom_fontuse-bangla-font.php:40
noprivwp_ajax_delete_custom_fontuse-bangla-font.php:41
WordPress Hooks 6
actioninituse-bangla-font.php:30
actionadmin_menuuse-bangla-font.php:36
actionadmin_inituse-bangla-font.php:37
actionadmin_enqueue_scriptsuse-bangla-font.php:38
actionwp_enqueue_scriptsuse-bangla-font.php:39
actionadmin_inituse-bangla-font.php:42
Maintenance & Trust

Use Bangla Fonts Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 27, 2025
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Use Bangla Fonts Developer Profile

osman sorkar

3 plugins · 1K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
99 days
View full developer profile
Detection Fingerprints

How We Detect Use Bangla Fonts

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/use-bangla-fonts/build/index.css/wp-content/plugins/use-bangla-fonts/build/index.js
Script Paths
/wp-content/plugins/use-bangla-fonts/build/index.js
Version Parameters
use-bangla-fonts/build/index.css?ver=use-bangla-fonts/build/index.js?ver=

HTML / DOM Fingerprints

CSS Classes
use-bangla-fonts-settings-containeruse-bangla-fonts-section-wrapperuse-bangla-fonts-field-groupuse-bangla-fonts-field-contentuse-bangla-fonts-css-sectionuse-bangla-fonts-font-listfont-items-gridfont-item
Data Attributes
name="use_bangla_fonts_options[custom_css]"id="use_bangla_fonts_options-custom_css"name="use_bangla_fonts_options[enabled_fonts][]"
FAQ

Frequently Asked Questions about Use Bangla Fonts