TypeSquare Webfonts for エックスサーバー Security & Risk Analysis

wordpress.org/plugins/xserver-typesquare-webfonts

エックスサーバー株式会社が提供する各レンタルサーバーサービスでWebフォントを利用できるプラグインです。

100K active installs v2.0.9 PHP + WP 5.2+ Updated Dec 4, 2025
fontswebfonts
99
A · Safe
CVEs total1
Unpatched0
Last CVEAug 7, 2024
Safety Verdict

Is TypeSquare Webfonts for エックスサーバー Safe to Use in 2026?

Generally Safe

Score 99/100

TypeSquare Webfonts for エックスサーバー has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Aug 7, 2024Updated 4mo ago
Risk Assessment

The xserver-typesquare-webfonts plugin version 2.0.9 exhibits a generally good security posture, with a significant number of code signals indicating adherence to best practices. The absence of any unprotected AJAX handlers, REST API routes, shortcodes, or cron events, combined with 100% of SQL queries using prepared statements and a high percentage of properly escaped output, are positive indicators. The presence of nonce and capability checks further strengthens its defenses. However, the taint analysis reveals a concerning pattern: three out of four analyzed flows have unsanitized paths. While no critical or high severity issues were flagged in the taint analysis for this version, this indicates a potential for path traversal vulnerabilities or unintended file access if these flows are not handled with extreme care. The plugin's vulnerability history, which includes one medium severity CVE related to missing authorization in the past, suggests a historical tendency towards authorization weaknesses. Although there are no currently unpatched CVEs, this pattern combined with the taint analysis findings warrants careful monitoring and thorough code review to ensure these unsanitized paths do not become exploitable.

Key Concerns

  • Unsanitized paths in taint analysis
  • Medium severity CVE in vulnerability history
  • Less than 100% output escaping
Vulnerabilities
1

TypeSquare Webfonts for エックスサーバー Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-43120medium · 5.3Missing Authorization

TypeSquare Webfonts <= 2.0.7 - Missing Authorization via typesquare_admin_init()

Aug 7, 2024 Patched in 2.0.8 (8d)
Code Analysis
Analyzed Mar 16, 2026

TypeSquare Webfonts for エックスサーバー Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
138 escaped
Nonce Checks
9
Capability Checks
4
File Operations
2
External Requests
2
Bundled Libraries
0

Output Escaping

87% escaped158 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

4 flows3 with unsanitized paths
<admin-root> (inc\admin-root.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

TypeSquare Webfonts for エックスサーバー Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionwp_dashboard_setupinc\admin-dashboard.php:16
actionwp_enqueue_scriptsts-webfonts-for-xserver.php:44
actionwp_headts-webfonts-for-xserver.php:45
actionpre_get_poststs-webfonts-for-xserver.php:46
filtermce_buttonsts-webfonts-for-xserver.php:383
actionadmin_menutypesquare-admin.php:28
actionadmin_menutypesquare-admin.php:29
actionadmin_inittypesquare-admin.php:30
actionadmin_noticestypesquare-admin.php:31
actionadmin_noticestypesquare-admin.php:32
actionsave_posttypesquare-admin.php:33
actionadmin_enqueue_scriptstypesquare-admin.php:34
Maintenance & Trust

TypeSquare Webfonts for エックスサーバー Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 4, 2025
PHP min version
Downloads1.4M

Community Trust

Rating0/100
Number of ratings0
Active installs100K
Developer Profile

TypeSquare Webfonts for エックスサーバー Developer Profile

XServer

2 plugins · 110K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
16 days
View full developer profile
Detection Fingerprints

How We Detect TypeSquare Webfonts for エックスサーバー

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/xserver-typesquare-webfonts/js/xserverv3.js
Script Paths
//webfonts.xserver.jp/js/xserverv3.js
Version Parameters
xserverv3.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-typesquare-font-theme
JS Globals
TypeSquare_ST
FAQ

Frequently Asked Questions about TypeSquare Webfonts for エックスサーバー