Web Font Display Security & Risk Analysis

wordpress.org/plugins/web-font-display

Webfont display plugin help you to resolve pagespeed insights error : "Ensure text remains visible during webfont load".

200 active installs v1.0 PHP + WP 6.0+ Updated Jun 17, 2022
font-awesome-fontsgoogle-fontswebfont-load
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Web Font Display Safe to Use in 2026?

Generally Safe

Score 85/100

Web Font Display has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "web-font-display" v1.0 plugin exhibits a very strong security posture based on the provided static analysis and vulnerability history. The absence of any detected dangerous functions, unescaped output, raw SQL queries, file operations, external HTTP requests, or taint flows suggests excellent coding practices regarding secure development. The plugin also benefits from a minimal attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events being exposed without proper authentication or permission checks. Furthermore, the lack of any known CVEs, past or present, indicates a history of responsible development and a lack of publicly disclosed vulnerabilities.

While the plugin appears robust, the complete absence of any nonces or capability checks across its entire (albeit zero) attack surface is a notable point. This is not necessarily a direct vulnerability in this specific version given the lack of entry points, but it highlights a potential area for improvement should the plugin evolve and introduce new functionalities that interact with user input or sensitive actions. In its current state, however, "web-font-display" v1.0 presents a very low risk to WordPress installations.

Key Concerns

  • No nonce checks on any entry points
  • No capability checks on any entry points
Vulnerabilities
None known

Web Font Display Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Web Font Display Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Web Font Display Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actioninitwfd-function.php:12
actionlitespeed_optm_cssjswfd-function.php:24
actionwp_print_styleswfd-function.php:28
actionwp_enqueue_scriptswfd-function.php:40
Maintenance & Trust

Web Font Display Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJun 17, 2022
PHP min version
Downloads3K

Community Trust

Rating60/100
Number of ratings1
Active installs200
Developer Profile

Web Font Display Developer Profile

AIS TECHNOLABS

6 plugins · 210 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Web Font Display

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/web-font-display/webfonts.min.css

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Web Font Display