
WP Responsive Auto Fit Text Security & Risk Analysis
wordpress.org/plugins/wp-responsive-slab-textWP Responsive Auto Fit Text allows you to create great, big, bold headlines that resize to the viewport width, with a WordPress shortcode.
Is WP Responsive Auto Fit Text Safe to Use in 2026?
Generally Safe
Score 91/100WP Responsive Auto Fit Text has a strong security track record. Known vulnerabilities have been patched promptly.
The wp-responsive-slab-text plugin v0.3 demonstrates a generally good security posture with several positive attributes. The static analysis reveals no dangerous functions, no raw SQL queries, and a high percentage of properly escaped output. Notably, there are no file operations or external HTTP requests, which significantly reduces potential attack vectors. The plugin also has a limited attack surface, with only two shortcodes as entry points, and importantly, no unprotected entry points detected.
However, there are a few areas that warrant attention. The absence of nonce checks and capability checks across all detected entry points is a significant concern. While the static analysis found no unprotected AJAX or REST API routes, the general lack of these crucial security mechanisms means that any future additions or modifications to these handlers, or even the existing shortcodes if they implicitly interact with backend functions, could be vulnerable. The vulnerability history shows a single medium severity CVE related to Cross-site Scripting, which, although patched, indicates a past vulnerability in how user input was handled. The fact that the last vulnerability was recorded in 2025 suggests it's a recent finding and may be a concern if the code hasn't been thoroughly reviewed since.
In conclusion, the plugin has strengths in its avoidance of common risky functions and its use of prepared statements. Nevertheless, the complete absence of nonce and capability checks is a substantial weakness that significantly elevates risk, as it leaves the plugin's functionality open to unauthorized execution or manipulation. The past XSS vulnerability, even if patched, serves as a reminder to be vigilant about input sanitization and output escaping.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
- Past medium severity XSS vulnerability
- 1 out of 2 shortcodes might have unescaped output
WP Responsive Auto Fit Text Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Responsive Auto Fit Text <= 0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Responsive Auto Fit Text Code Analysis
Output Escaping
WP Responsive Auto Fit Text Attack Surface
Shortcodes 2
WordPress Hooks 1
Maintenance & Trust
WP Responsive Auto Fit Text Maintenance & Trust
Maintenance Signals
Community Trust
WP Responsive Auto Fit Text Alternatives
Fit To Width – CSS-only stretchy text
fit-to-width
Automatically adjusts the text to fit the width of its container. No JavaScript.
Use Any Font | Custom Font Uploader
use-any-font
Upload custom fonts with custom font uploader. Auto converts to woff2 for better performance. Self-hosted, GDPR compliant, and easy custom font plugin
Easy Google Fonts
easy-google-fonts
Adds google fonts to any theme without coding and integrates with the WordPress Customizer automatically for a realtime live preview.
Orphans
sierotki
Supports the grammar rule for orphan words at the end of a line.
Self-Hosted Google Fonts
selfhost-google-fonts
Automatically self-host all the Google Fonts on your site. Plug and play.
WP Responsive Auto Fit Text Developer Profile
1 plugin · 600 total installs
How We Detect WP Responsive Auto Fit Text
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-responsive-auto-fit-text/js/jquery.slabtext.min.js/wp-content/plugins/wp-responsive-auto-fit-text/css/wp-responsive-auto-fit-text.css/wp-content/plugins/wp-responsive-auto-fit-text/js/jquery.slabtext.min.js/wp-content/plugins/wp-responsive-auto-fit-text/js/jquery.slabtext.min.js?ver=/wp-content/plugins/wp-responsive-auto-fit-text/css/wp-responsive-auto-fit-text.css?ver=HTML / DOM Fingerprints
slabtext-wrapperdata-slabtext-viewport-breakpointslabTextDatastSstEtxtSC_SCRIPTSSLAB_TEXT_LINE<div id="slabTextclass="slabtext-wrapper"></div>