Vazir Font Security & Risk Analysis

wordpress.org/plugins/vazir-font

فونت وزیرمتن برای وردپرس

700 active installs v1.0 PHP 5.6+ WP 5.0+ Updated May 15, 2022
farsifontpersianvazir
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Vazir Font Safe to Use in 2026?

Generally Safe

Score 85/100

Vazir Font has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The vazir-font plugin v1.0 exhibits a very strong security posture based on the provided static analysis. The complete absence of any identified entry points, including AJAX handlers, REST API routes, shortcodes, or cron events, significantly reduces the potential attack surface. Furthermore, the code analysis shows excellent secure coding practices with no dangerous functions, all SQL queries using prepared statements, and all outputs properly escaped. The lack of file operations, external HTTP requests, and importantly, the absence of nonce and capability checks, while seemingly concerning in isolation, are likely a reflection of the plugin's simple functionality and lack of user-interactive features.

The taint analysis also indicates no security concerns, with zero flows exhibiting unsanitized paths. The vulnerability history is equally clean, with no recorded CVEs, past or present. This historical data suggests a well-maintained plugin or one that has not been a target for exploit development. However, the complete absence of capability checks and nonce checks across all potential entry points (though none are identified) is a potential weakness if the plugin's functionality were to expand in the future without corresponding security implementations. The plugin's current simplicity is its greatest security asset.

In conclusion, vazir-font v1.0 appears to be highly secure due to its minimal attack surface and adherence to secure coding principles in its current form. The lack of any identified vulnerabilities or concerning code patterns is a significant strength. The only notable area for improvement, should the plugin evolve, would be the implementation of robust authorization and nonce checks for any future added functionalities to maintain this strong security posture.

Vulnerabilities
None known

Vazir Font Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Vazir Font Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Vazir Font Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_enqueue_scriptsvazir-font.php:19
actionwp_enqueue_scriptsvazir-font.php:20
actionlogin_enqueue_scriptsvazir-font.php:21
Maintenance & Trust

Vazir Font Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedMay 15, 2022
PHP min version5.6
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs700
Developer Profile

Vazir Font Developer Profile

sadeghpm

1 plugin · 700 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Vazir Font

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vazir-font/asset/css/vazir-font-dashboard.css/wp-content/plugins/vazir-font/asset/css/vazir-font.css
Version Parameters
vazir-font/asset/css/vazir-font-dashboard.css?ver=vazir-font/asset/css/vazir-font.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Vazir Font