DEV Community

hub
hub

Posted on

WordPress-WP-Jobmanager and the Astoundify-theme Jobify: fetching Google-data: critical issues for all users

WordPress-WP-Jobmanager and the Astoundify-theme Jobify: fetching Google-data: a nightmare for all users..

a newly dicussion pointed out that there are important and sericous security-risks in relation to Google-Fonts: and yes – this is a topic that we might be concearnd since we all use themes. and many many of us use – jobify for example.

to begin with the beginning:

cf: WordPress Theme Authors Are Moving to Host Fonts Locally
https://wptavern.com/wordpress-theme-authors-are-moving-to-host-fonts-locally

The WordPress Themes team is poised to change its guidelines on remote hosting Google Fonts and is once again strongly urging theme authors to host their fonts locally. Yoast-sponsored contributor Ari Stathopoulos published an update today to answer some questions the team has been receiving about fonts in themes: Historically, WordPress themes hosted in the w.org themes repository were not allowed to use third-party resources. This included images, javascript files, CSS files, webfonts, and other assets loaded from a remote server. Google fonts was an exception to this rule because, at the time, there was no reliable way to implement locally-hosted webfonts, and typography is an integral part of a theme’s design. Google fonts, however, can no longer be considered an exception to this guideline because of the GDPR and privacy implications.

see more: Ari Stathopoulos: Using locally-hosted Google fonts in themes This post is a follow-up to Complying with GDPR when using Google Fonts, aiming to answer some questions that have been popping up in team meetings and social media.

Background: Well Jobify, one of the theme that is used very often on Wp-Job-Manager we have to state:

cf. Astoundify-developer:

In relation to your reply here, yes indeed Jobify does use the Google fonts on that section of the customizer on your WordPress site. However, I do believe these are hosted from our server.

Question: does this help here – if the Astoundify-devs host the fonts on their server – are we able to use the theme without any risk!?

this is a topic that has to be discussed here – since the jobify theme is the de-facto-theme for WP-Jobmanager… We need to make sure that the big big community of Wp-Job-manager-User do not run into serious issues and conflicts with court.

look forward to a fruitful discussion here:

see more infos – see more data – and have an overview on the actual discussion:

cf. a. WordPress Theme Authors Are Moving to Host Fonts Locally https://wptavern.com/wordpress-theme-authors-are-moving-to-host-fonts-locally

The WordPress Themes team is poised to change its guidelines on remote hosting Google Fonts and is once again strongly urging theme authors to host their fonts locally. Yoast-sponsored contributor Ari Stathopoulos published an update today to answer some questions the team has been receiving about fonts in themes:
Historically, WordPress themes hosted in the w.org themes repository were not allowed to use third-party resources. This included images, javascript files, CSS files, webfonts, and other assets loaded from a remote server.

b. German Court Fines Website Owner for Violating the GDPR by Using Google-Hosted Fonts: https://wptavern.com/german-court-fines-website-owner-for-violating-the-gdpr-by-using-google-hosted-fonts

read more here:

Latest comments (0)