
Web Font Display Security & Risk Analysis
wordpress.org/plugins/web-font-displayWebfont display plugin help you to resolve pagespeed insights error : "Ensure text remains visible during webfont load".
Is Web Font Display Safe to Use in 2026?
Generally Safe
Score 85/100Web Font Display has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "web-font-display" v1.0 plugin exhibits a very strong security posture based on the provided static analysis and vulnerability history. The absence of any detected dangerous functions, unescaped output, raw SQL queries, file operations, external HTTP requests, or taint flows suggests excellent coding practices regarding secure development. The plugin also benefits from a minimal attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events being exposed without proper authentication or permission checks. Furthermore, the lack of any known CVEs, past or present, indicates a history of responsible development and a lack of publicly disclosed vulnerabilities.
While the plugin appears robust, the complete absence of any nonces or capability checks across its entire (albeit zero) attack surface is a notable point. This is not necessarily a direct vulnerability in this specific version given the lack of entry points, but it highlights a potential area for improvement should the plugin evolve and introduce new functionalities that interact with user input or sensitive actions. In its current state, however, "web-font-display" v1.0 presents a very low risk to WordPress installations.
Key Concerns
- No nonce checks on any entry points
- No capability checks on any entry points
Web Font Display Security Vulnerabilities
Web Font Display Code Analysis
Web Font Display Attack Surface
WordPress Hooks 4
Maintenance & Trust
Web Font Display Maintenance & Trust
Maintenance Signals
Community Trust
Web Font Display Alternatives
Custom Fonts – Host Your Fonts Locally
custom-fonts
Custom Fonts is a powerful WordPress plugin that allows you to upload your own custom fonts or choose from a vast collection of Google Fonts, all host …
Fonts Plugin | Use Google Fonts, Adobe Fonts or Upload Fonts
olympus-google-fonts
The easiest to customize fonts in WordPress. Optimized for Speed. 1000+ font choices. Supports Google Fonts, Adobe Fonts and Upload Fonts.
Use Any Font | Custom Font Uploader
use-any-font
Upload custom fonts with custom font uploader. Auto converts to woff2 for better performance. Self-hosted, GDPR compliant, and easy custom font plugin
Disable and Remove Google Fonts | GDPR & DSGVO friendly
disable-remove-google-fonts
Improve frontend performance by disabling Google Fonts. GDPR and DSGVO friendly.
Easy Google Fonts
easy-google-fonts
Adds google fonts to any theme without coding and integrates with the WordPress Customizer automatically for a realtime live preview.
Web Font Display Developer Profile
6 plugins · 210 total installs
How We Detect Web Font Display
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/web-font-display/webfonts.min.css