
WP Typograph Full Security & Risk Analysis
wordpress.org/plugins/wp-typograph-fullRussian typography for Wordpress. Full version with settings.
Is WP Typograph Full Safe to Use in 2026?
Generally Safe
Score 85/100WP Typograph Full has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-typograph-full" v2.3.5 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by not initiating external HTTP requests, performing file operations, or using bundled libraries. The absence of known CVEs and a clean vulnerability history are strong indicators of past security diligence.
However, the static analysis reveals significant concerns. The presence of dangerous functions like `preg_replace(/e)` and `create_function` is a red flag, as these can be exploited for code execution if user input is not meticulously sanitized. While the taint analysis shows no critical or high-severity issues in the flows analyzed, the existence of two flows with unsanitized paths is still worrying and could lead to vulnerabilities if they interact with dangerous functions or sensitive data.
Furthermore, the lack of any nonce checks or capability checks, coupled with zero unprotected entry points in the attack surface, is peculiar. While this might suggest that all interactions are indirectly protected, it also means there's no explicit defense-in-depth at the plugin's direct entry points. The overall conclusion is that while the plugin has a clean vulnerability history, the static analysis highlights potential weaknesses related to dangerous function usage and unsanitized data flows that require careful attention and potential remediation.
Key Concerns
- Dangerous function: preg_replace(/e)
- Dangerous function: create_function
- Taint flows with unsanitized paths (2)
- No nonce checks
- No capability checks
- Unescaped output (1 of 10)
WP Typograph Full Security Vulnerabilities
WP Typograph Full Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
WP Typograph Full Attack Surface
WordPress Hooks 15
Maintenance & Trust
WP Typograph Full Maintenance & Trust
Maintenance Signals
Community Trust
WP Typograph Full Alternatives
WP Typograph Lite
wp-russian-typograph
Russian typography for Wordpress. Lite version.
Allow Comments to Old Posts
allowcomments
Allow comments to posts with custom field "allow_comments" even if option 'close comments to old posts' is on.
Remove Double Space
remove-double-space
Remove duplicate whitespace in between sentences or elsewhere within posts. Useful if multiple contributors use different styles for sentence spacing.
По български
bgstyle
Помага за по-доброто оформление за публикации на български език
Post Typographer
post-typographer
Adds non-breaking spaces, `` tags, common spaces, tags and dashes where needed. Works with English texts only.
WP Typograph Full Developer Profile
6 plugins · 8K total installs
How We Detect WP Typograph Full
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-typograph-full/typograph.css/wp-content/plugins/wp-typograph-full/typograph.jswp-typograph-full/typograph.css?ver=wp-typograph-full/typograph.js?ver=