OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. icon

OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy.

Automatically cache Google Fonts locally to improve page load times and meet GDPR requirements without manual configuration. With over 300,000 active installations and a 4.7/5 rating, this plugin ranks in the top 1% of all WordPress plugins.

Generated on 8 Jul 2026. Score and stats mentioned may differ from current live data.

  • #137 Global Rank
  • 300K+ active installs
  • 4.7/5 212 ratings
  • Since 2018 8 years active

PF Score (About PF Scores)

PF Score is not a quality guarantee. It is a ranking based on available public signals.

Platinum93.2
Platinum
Gold
Silver
Bronze
Low

Score Breakdown

91.3
Popularity 40% 300K+ active installs
91.1
Reputation 35% 4.7★ from 212 ratings
99.2
Freshness 25% Updated 8 days ago

No active penalty — 4 historical CVEs, resolved — details

Download Trends

Loading download data…

Vulnerabilities

4 Total
4 Patched
0 Active
100% Resolved rate
CWE-862 · Missing Authorization

The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cross-Site Scripting due to a missing capability check on the update_settings() function hooked via admin_init in all versions up to, and including, 5.7.9. This makes it possible for unauthenticated attackers to update the plugin's settings which can be used to inject Cross-Site Scripting payloads and delete entire directories. PLease note there were several attempted patched, and we consider 5.7.10 to be the most sufficiently patched.

8.6 High Affected All – 5.7.9 Patched in ✓ 5.7.10 Published 2 Jan 2024 CVE CVE-2023-6600
CWE-22 · Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The OMGF | Host Google Fonts Locally WordPress plugin before 4.5.12 does not validate the cache directory setting, allowing high privilege users to use a path traversal vector and delete arbitrary folders when uninstalling the plugin

4.9 Medium Affected All – 4.5.11 Patched in ✓ 4.5.12 Published 1 Dec 2021 CVE CVE-2021-25021
CWE-22 · Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The OMGF WordPress plugin before 4.5.4 does not escape or validate the handle parameter of the REST API, which allows unauthenticated users to perform path traversal and overwrite arbitrary CSS file with Google Fonts CSS, or download fonts uploaded on Google Fonts website.

9.1 Critical Affected All – 4.5.3 Patched in ✓ 4.5.4 Published 23 Aug 2021 CVE CVE-2021-24638
CWE-284 · Improper Access Control

The OMGF WordPress plugin before 4.5.4 does not enforce path validation, authorisation and CSRF checks in the omgf_ajax_empty_dir AJAX action, which allows any authenticated users to delete arbitrary files or folders on the server.

8.1 High Affected All – 4.5.3 Patched in ✓ 4.5.4 Published 23 Aug 2021 CVE CVE-2021-24639

Vulnerability data provided by Wordfence Intelligence (opens in a new tab). CVE data: Copyright 1999–2026 The MITRE Corporation. CVE Terms of Use (opens in a new tab).

Support Statistics

1 Support threads
1 Resolved
100% Resolution rate

About OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy.

The original Google Fonts self-hosting plugin. Automagically caches your fonts locally — no configuration (or brains) required!

OMGF can be downloaded for free without any paid subscription from the official WordPress repository.

Trusted by 300,000+ WordPress sites. The original Google Fonts self-hosting plugin.

OMGF removes the connection between your site and Google’s font servers, eliminating the DNS lookups and render-blocking requests that slow down LCP and TTFB — while making your site GDPR/DSGVO-compliant in the process. German courts have ruled that loading Google Fonts directly violates GDPR, since visitor IPs get logged by Google. OMGF closes that gap entirely: nothing leaves your server.

Install it and it works immediately. No setup required, though there’s plenty to fine-tune if you want to.

Detection, Out of the Box

OMGF scans your site for Google Fonts, Bunny Fonts (fonts.bunny.net), and Jetpack CDN (fonts-api.wp.com) and downloads them to your own server automatically. It even automatically detects and optimizes Google Fonts loaded by Elementor.

Free Features

Resource hints cleanup — Strips leftover preconnect, dns-prefetch, and preload hints pointing at fonts.googleapis.com and fonts.gstatic.com — dead weight once your fonts are self-hosted.

font-display control — Force font-display: swap (or block, fallback, optional, auto) on your Google Fonts, fixing “Ensure text remains visible during webfont load” in Lighthouse and PageSpeed Insights.

Performance Checker — Keeps an eye on your setup and flags what’s costing you points: unused subsets, unused weights, missing preloads above the fold, and layout shift from fonts loading late.

Google Fonts checker — Pings you when a theme or plugin update introduces new Google Fonts that haven’t been processed yet.

Manual control — Globally unload font families or weights you don’t need. Preload the ones that matter above the fold.

Integrates with your stack — OMGF works alongside the optimization plugins and page builders you’re already running, including Autoptimize, FlyingPress, Kinsta, LiteSpeed Cache, SiteGround Speed Optimizer, W3 Total Cache, WP Fastest Cache, WP-Optimize, WP Rocket, WP Super Cache, Elementor, Divi, Beaver Builder, Bricks, Oxygen, and Visual Composer.

OMGF Pro

Where the free version covers the fundamentals, Pro removes the manual work entirely.

Smart Optimize — Measures, on real visitor pageviews, exactly which fonts, subsets, and weights get used above the fold. Preloads what matters, strips what doesn’t. No configuration, no guessing — just measured results.

Magic Fallbacks — Generates system font fallbacks mathematically tuned to match each Google Font’s real metrics (size-adjust, ascent-override), so text doesn’t jump around while fonts load. Zero CLS, calculated automatically per font.

Deeper detection — Pro reaches fonts the free version and competitors don’t touch:
– Inline <style> blocks with @font-face or @import
– Local and externally hosted stylesheets using @import
– Web Font Loader (webfont.js)
– Async, JS-injected Google Fonts loaded at runtime
– WordPress’s Font Manager (or Font Library, since WP 7.0)
– Variable Fonts (fonts.googleapis.com/css2)
– Material Icons

Global font-display — Extends font-display control to every font on your site, not just Google Fonts.

Everything else:
– Automatic Multisite and WPML support
– Serve fonts and stylesheets from your own CDN or custom path
– Replace font families with system fonts entirely
– Whitelabel stylesheets — strip OMGF branding and comments for smaller file sizes
– Developer Mode for safely migrating between dev, staging, and production

Get OMGF Pro | Documentation | Tested Plugins & Themes

Screenshots

OMGF's Local Fonts screen. These settings affect the downloaded files and generated stylesheet(s).

OMGF's Local Fonts screen. These settings affect the downloaded files and generated stylesheet(s).

The dashboard offers a quick overview of possible configurational issues (and solutions), the status of cached fonts/stylesheets along with quick links to simple management tasks e.g., Empty Cache and Configure/Remove.

The dashboard offers a quick overview of possible configurational issues (and solutions), the status of cached fonts/stylesheets along with quick links to simple management tasks e.g., Empty Cache and Configure/Remove.

After you've completed configuring OMGF, the Optimize Local Fonts section will allow you to tweak all of your Google Fonts stylesheets by e.g., unloading unused fonts and/or preloading fonts above the fold.

After you've completed configuring OMGF, the Optimize Local Fonts section will allow you to tweak all of your Google Fonts stylesheets by e.g., unloading unused fonts and/or preloading fonts above the fold.

Advanced Settings. Change these to make OMGF work with your configuration (if needed). The default settings will suffice for most configurations.

Advanced Settings. Change these to make OMGF work with your configuration (if needed). The default settings will suffice for most configurations.

Ratings & Reviews

Recent Reviews

Loading reviews…

View all reviews on WordPress.org (opens in a new tab)

Changelog

6.3.10

  • Note: this release detects stylesheets which were skipped before, so optionally run Save & Optimize once after updating to add them to your cache. Nothing breaks if you don’t.
  • Fixed: Google Fonts stylesheets whose href attribute contains a line break (or tab) weren’t detected during Save & Optimize, while browsers loaded them just fine, because they strip those characters from URLs before requesting them. OMGF now does the same, so these stylesheets are detected and optimized like any other.
  • Fixed: Google Fonts checker flagged font faces as unused even when an element on the page referenced them in its computed style. Font faces defining a unicode-range were compared against an identifier which the detected font faces never contain, so the check always passed. As a result, fonts used by elements which aren’t rendered on page load (e.g., in tabs, accordions, and modals) could be marked as unused. That check now only covers elements which aren’t laid out, so unused subsets of a font used elsewhere on the page are still detected.

6.3.9

  • Fixed: SVGs and other assets from fonts.gstatic.com would be flagged as false positives by Google Fonts checker.
  • Improved: added Beehiiv to Iframes Loading Fonts.
  • Fixed: The settings save handler no longer stores a malformed (scalar) value for options that must be arrays (e.g., when a proxy or security plugin flattens the array parameters), and self-heals a previously corrupted option on the next save. This prevents a fatal ‘Cannot access offset of type string on string’ error on the Optimize Fonts screen. Add-ons can register their own array-based options via the omgf_settings_array_options filter.

6.3.8 | June 25th, 2026

  • XSS: Hardened security by adding capability and nonce checks to Save & Optimize action.

6.3.7 | June 16th, 2026

  • Added: omgf_frontend_process_preloads action, which is used by OMGF Pro for coming up Smart Optimize improvements.

6.3.6 | June 4th, 2026

  • Tested with WP 7.0.

6.3.5 | May 13th, 2026

  • Fixed: Google Fonts and Performance Checker didn’t run when Disable Admin Bar Menu was enabled.

6.3.4 | April 13th, 2026

  • Code improvements to facilitate UX in OMGF Pro.

6.3.3 | April 10th, 2026

  • Improved: Performance Checker now also checks Cumulate Layout Shifting (CLS) caused by fonts.
  • Some minor UI fixes.

6.3.2 | March 31st, 2026

  • Fixed: Uncaught Error: Call to undefined function is_plugin_active(), which was introduced in 6.3.1.

6.3.1

  • Fixed: flushing the cache after running Save & Optimize didn’t work.
  • Added: compatibility with the official Cloudflare plugin.

6.3.0 | March 30th, 2026

  • Improved: clarified the dialog shown in the Performance Checker.
  • Improved: OMGF now flushes the CSS cache of the most popular caching plugins after running Save & Optimize:
    • Autoptimize
    • FlyingPress
    • Kinsta Cache
    • LiteSpeed Cache
    • SiteGround Optimizer
    • W3 Total Cache
    • WP Fastest Cache
    • WP-Optimize
    • WP Rocket
    • WP Super Cache
  • Improved: OMGF now flushes its own (third party) cache when editing options and/or pages/posts in the following themes/page builders:
    • Avada
    • Beaver Builder
    • Bricks Builder
    • Divi
    • Elementor
    • Oxygen
  • Improved: When you switch themes, update permalinks or update a plugin, OMGF will now also flush third party stylesheets it’s cached.

6.2.0 | March 23rd, 2026

  • Extended the Google Fonts checker with a Performance Checker, which checks how fonts are performing on your site in 3 areas:
    • Unused Subsets,
    • Unused Font styles/weights,
    • Missing Preloads.
      If it finds any issues, it’ll suggest solutions.

6.1.4

  • Improved: options are now retrieved much more efficiently.
  • Improved: minor security fixes.
  • Deprecated: omgf_frontend_preloaded_fonts and omgf_frontend_optimized_fonts are deprecated and will be removed in a future release.
    They are replaced by omgf_filter_preloaded_fonts and omgf_filter_optimized_fonts.

6.1.3

  • Coincidentally found a bug that has been haunting me for years, that’s why I’m releasing this quick patch release.
  • Fixed: in some scenarios, unloaded_stylesheets would be stored as an array with one empty element in the database.

6.1.2 | February 20th, 2026

  • Fixed: if the expected MIME type of the downloaded file didn’t match, a class OMGF\OMGF exception would be thrown.
  • Dev: Updated CI tools.

6.1.1 | January 26th, 2026

  • Fixed: font-weights would sometimes break when Smart Slider 3 or Groovy Menu was enabled.

6.1.0 | January 21st, 2026

  • Improved: OMGF now runs on wp-login.php.

6.0.11 | December 1st, 2025

  • Tested with WP 6.9
  • Improved: Renamed Divi/Elementor compatibility to just Divi compatibility, since Elementor compatibility is now always on.
  • Added: Colibri WP theme to list of themes that require additional configuration.
  • Fixed: an Uncaught TypeError would appear in the admin screen on some instances.

6.0.10 | October 10th, 2025

  • Improved: subset and font-family detection to avoid false positives.
  • Fixed: If no subset could be found, font filenames would be erroneously prepended with a dash.

6.0.9 | October 9th, 2025

  • Improved: Google Fonts Checker now shows 5 results (pages) per found fonts request.
  • Improved: clarified error message shown by Google Fonts Checker.
  • Improved: Improved code related to Downloading and Optimization process to be more restrictive.

6.0.8 | October 1st, 2025

  • Fixed: compatibility fix for Smart Slider 3, didn’t run on Smart Slider 3 Pro.
  • Fixed: syntax error in “Update available” message, would break JS execution on Plugins page.
  • Improved: use new $params variable in filter, to prevent double POST cleanup.

6.0.7 | August 26th, 2025

  • Fixed: removed trailing commas on some function calls to prevent errors in PHP 7.2 and lower.
  • Minimum required PHP version is now 7.3, because it’ll make my life easier and PHP 7.2 has been EOL for ages.

6.0.6 | July 30th, 2025

  • Improved: PHP 8.3 compatibility.
  • Fixed: Unloads (Don’t Load) now work properly on Elementor stylesheets.
  • Improved: logic to process unloaded font styles in stylesheets is more streamlined now.
  • Fixed: a fatal error which occurred if nothing was selected in the Advanced Settings > Used Subsets option.

6.0.5 | July 7th, 2025

  • Fixed: class WPTT not found error. Oops!

6.0.4 | July 4th, 2025

  • Added: compatibility for themes/plugins using the WPTT webfont loader.
  • Improved: Optimize Local Fonts section is now full width, like the Dashboard.
  • Improved: Moved Test Mode into the Dashboard section.

6.0.3 | June 24th, 2025

  • Added: Smart Preload (Pro) promotional option.
  • Added: Compatibility for the upcoming Elementor v3.30 release.
  • Improved: Compatibility fixes are now moved into one place, and are only loaded on the condition of the respective plugin actually being activated.
  • Improved: All settings related to fonts optimization are now grouped in the Optimize Local Fonts section under the Local Fonts tab.
  • Several code improvements.

6.0.2 | June 12th, 2025

  • Improved: the Google Fonts checker now runs through its own API endpoint, instead of WP’s AJAX actions.
  • Improved: the Disable Admin Bar Menu option now also disables the Google Fonts checker.
  • Added: Real Cookie Banner, Borlabs Cookie Banner, and Trustmary to the list of plugins which require additional configuration.
  • Minor refactors for cleaner code and to fix minor security flaws.

6.0.1 | May 27th, 2025

  • Fixed: Frontend Assets would still load, even when Disable Top Admin Bar Menu option was enabled.
  • Fixed: some themes (like Enfold) are incompatible with wp-util. Refactored wp-util dependencies to vanilla JS in Google Fonts checker to no longer rely on it.
  • Improved: really long URLs in the Dashboard are now wrapped.
  • Fixed: when OMGF Pro isn’t installed, Fallback Font Stack shouldn’t be enabled.

6.0.0 – **2000 IQ edition** | May 26th, 2025

  • Added: Google Fonts checker, which will notify you when a plugin or theme has added Google Fonts OMGF can’t process (and provide a solution!)
  • Improved: the menu in the Top Admin Bar now has a stoplight, which notifies you if there are any Google Fonts and/or configurational issues. It’ll show green if all is well.
  • Improved: the Task Manager is superseded by a brand-new Dashboard, which will give you a quick overview of:
    • If OMGF was able to process all Google Fonts on your site, and if not; show you where they were found with possible solutions.
    • If there were any configurational issues (e.g., known conflicts with other plugins, etc.).
    • Cache status,
    • Simple cache management tasks: Empty and Refresh.
  • Improved: The settings screen got a fresh new coat of paint, fully aligned with Daan.dev’s new look.
  • Improved: Settings were moved around to move logical places:
    • The Detection Settings tab has been removed,
    • The Local Fonts tab is now fully dedicated to informing you about your Local Google Fonts configuration.
    • All options, that’re not directly related to Locally Hosting Google Fonts but are directed more at optimization, are now moved to the Advanced Settings tab.
  • Improved: Optimize for (D)TAP is now renamed to the more appropriate Developer Mode.
  • Improved: Mailerlite users are now made aware of the fact that it loads iframes loading Google Fonts.
  • Improved: if Disable Admin Bar Menu (prev. Disable Quick Access Menu) is enabled, the Admin Bar Menu will still show if there are issues to notify the administrators.
  • Removed a bunch of old upgrade/update notifications.
  • Tons of bug fixes and code and security improvements.

5.9.3 | May 16th, 2025 – THE LAST PATCH RELEASE BEFORE **OMGF V6!**

  • Tested with WP 6.8
  • Added: compatibility with OptimizePress 3 theme
  • Fixed: Variable font weights weren’t processed properly during optimization.
  • Fixed: Update notices weren’t displayed properly.
  • Various small bugfixes.

[ Changelog shortened … ]

5.0.0 – **The Better, Bigger, Faster, Stronger, Cooler, Awesome-er Edition** | March 4th, 2022

  • Added: Parse entire HTML document for Google Fonts stylesheets (instead of just wp_head())
  • Added: Merged both Optimization Modes option into one automatically running option:
    – A first scan is done upon Save & Optimize,
    – A quick check is done on pageload, to see if other Google Fonts are found than the ones already found, and if so, they’re downloaded and replaced on-the-fly.
  • Enhanced: The Download API is replaced for an easier, leaner, and faster alternative and no longer uses the WordPress API.
    – If the first request fails, a mirror is used to retry the request, before throwing an error.
    – Fixes rest_no_route errors in some configurations.
  • Enhanced: The Task Manager now offers a quick overview of downloaded stylesheets and their status, along with simple management tasks, e.g. cache flush, configure stylesheet, and/or remove.
    – When cache is marked as stale, it’s now possible to refresh the cache and maintain your stylesheet configuration.
  • Added: Resource hints enqueued in wp_resource_hints() are now properly removed.
  • Fixed: Smart Slider 3 compatibility.
  • Several bugfixes, UX improvements, and code optimizations.

[ Changelog shortened … ]

4.0.0 | September 30th, 2020

  • OMGF now runs fully automatic to replace/remove Google Fonts from your pages using OMGF’s new Download API. No initial configuration required!
    • This means that if you use different fonts on different pages, all of them will be cached and served locally.
  • HUGE performance increase in OMGF’s automatic replacing/removing methods.
  • Major overhaul of Settings Page:
    • Removed Extensions Tab
    • Some settings were moved to a new tab: Basic Settings.
    • Improved Welcome and Documentation tab.
    • Clarified option descriptions.
  • Removed ‘Generate Stylesheet’ tab, which’ll be released in a separate add-on plugin soon.
  • Removed ‘Use Web Font Loader?’ option, because it causes Cumulative Layout Shift and will not work with OMGF’s new Auto Replace feature.
  • Removed ‘Remove Version Parameter’ option, because it has become obsolete. The new detection method uses the initial script’s version, if set.
  • Font Preloading is temporarily removed and will be re-introduced (in a different form, along with new features) in a later release.

[ Changelog shortened … ]

3.0.0

OMGF – CORONA EDITION
* Moved Welcome-panel to the side.
* wp_remote_get() is now used instead of cURL.
* Complete code overhaul to increase performance and UX.
* Notices and errors are now more explanatory and dismissable.
* Fixed several bugs.
* OMGF now uses wp_options table, instead of own tables.
* Old tables are removed and data is migrated.
* Auto detect now works better than ever.
* Search now works bug free.
* WordPress’ default admin fonts no longer show up as results.

[ Changelog shortened … ]

2.0.0

Added Typekit’s Web Font Loader to allow loading fonts asynchronously.

[ Changelog shortened… ]

1.0

First release! No changes so far!

Alternatives to OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy.

Other WordPress plugins serving a similar purpose, ranked by relevance and PF Score.

Platinum92.0
GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice for CCPA, EU Cookie Law icon

GDPR Cookie Compliance

Displays cookie consent banners to comply with GDPR, CCPA, and EU privacy regulations.

★ 4.6/5·300K+ installs·Updated 21 Jul 2026
Platinum85.8
Disable and Remove Google Fonts | GDPR & DSGVO friendly icon

Disable and Remove Google Fonts

Disable Google Fonts to improve performance and meet GDPR compliance requirements.

★ 4.5/5·100K+ installs·Updated 16 Jul 2026
Gold84.3
Shariff Wrapper icon

Shariff Wrapper

Share buttons that comply with GDPR and respect visitor privacy by default.

★ 4.9/5·30K+ installs·Updated 15 May 2026
Platinum98.9
Widgets for Google Reviews icon

Widgets for Google Reviews

Display Google reviews on your WordPress site to build trust and showcase customer ratings.

★ 4.9/5·900K+ installs·Updated 18 Aug 2026
Platinum98.8
WP Fastest Cache – WordPress Cache Plugin icon

WP Fastest Cache – WordPress Cache Plugin

Caching tool that accelerates site performance through simplified page caching and Core Web Vitals optimization.

★ 4.9/5·1.0M+ installs·Updated 3 Aug 2026
Platinum98.4
WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance icon

WP-Optimize

Caching plugin that optimizes images, cleans databases, and minifies code for improved WordPress performance.

★ 4.8/5·1.0M+ installs·Updated 13 Aug 2026
Platinum98.1
Compliance by Hu-manity.co icon

Compliance by Hu-manity.co

Consent management and compliance tool supporting GDPR, CCPA, and ePrivacy regulations with autoblocking functionality.

★ 4.8/5·900K+ installs·Updated 14 Aug 2026
Platinum98.1
CookieYes – Cookie Banner for Cookie Consent (Easy to setup GDPR/CCPA Compliant Cookie Notice) icon

CookieYes

Display cookie consent banners and manage GDPR and CCPA compliance requirements on WordPress sites.

★ 4.8/5·1.0M+ installs·Updated 3 Aug 2026
Platinum97.8
Complianz GDPR/CCPA Cookie Consent Banner icon

Complianz GDPR/CCPA Cookie Consent Banner

Configure cookie banners, consent policies, and privacy compliance using an automated wizard and scanner.

★ 4.7/5·1.0M+ installs·Updated 18 Aug 2026
Platinum95.0
Fonts Plugin | Google Fonts, Adobe Fonts & Upload Fonts icon

Fonts Plugin

Change website typography using Google Fonts, Adobe Fonts, or custom uploads with live preview.

★ 5/5·200K+ installs·Updated 12 Aug 2026
Platinum94.9
GA Google Analytics – Connect Google Analytics to WordPress icon

GA Google Analytics

Embed Google Analytics tracking code and access multiple tracking features for WordPress sites.

★ 4.9/5·400K+ installs·Updated 10 Aug 2026
Platinum94.0
Site Kit by Google – Analytics, Search Console, AdSense, Speed icon

Site Kit by Google

Integrates Google Analytics, Search Console, AdSense, and PageSpeed Insights into WordPress dashboards.

★ 4.2/5·5.0M+ installs·Updated 10 Aug 2026