App package auditing
Check iOS and Android packages for font compliance before launch.
FontReport analyses fonts across websites, PDFs and supported app packages, identifies their sources, and provides evidence to help assess potential licencing considerations. It is built for designers, developers, agencies and enterprise teams that need an accurate, repeatable view of font usage.
FontReport performs detailed technical analysis by:
Standard scans cover public web pages. Enterprise extends auditing to mobile apps and watched folders, with a running record of what’s already compliant.
Check iOS and Android packages for font compliance before launch.
PDFs are monitored automatically as they are added to a shared folder.
A single, standing record of which fonts are already compliant.
Also included: scheduled scans with email alerts, browser rendering for JavaScript-injected fonts, static IP allowlisting, 365-day history, custom scan limits and team access.
Multi-page scanning with CSS and JavaScript file analysis, direct font metadata extraction, and categorization of fonts by type (commercial, free and system fonts). Shows exactly which files and pages reference each font across your website.
Font foundries now have sophisticated tools to detect unlicensed usage across the web. What was once rarely enforced has become a real business risk, making proactive font auditing essential for website owners.
No more manually digging through CSS files or asking developers what fonts are installed. Automatically discovers fonts you didn't know existed - from third party theme/plugin fonts to old fonts hiding in your codebase.
Font licencing has always been complex, but the stakes have never been higher. Traditional methods for tracking font usage across websites are limited and time-consuming.
Font foundries and licensing companies now have sophisticated tools for discovering unlicensed font usage across the web, making it easier than ever for rights holders to identify potential licensing violations and pursue legal action. What was once rarely enforced has become a legitimate business concern that requires proactive management.
FontReport addresses this gap by providing comprehensive, automated font discovery across entire websites, giving you the visibility needed to identify fonts that may require licence verification and to avoid potential legal disputes.
FontReport scans website code and styles to identify fonts across the pages included in a scan. Enterprise options extend coverage to browser-rendered content, PDFs, shared Google Drive folders and supported app packages. Some scenarios still need manual checks:
Important: FontReport is an analysis tool that provides information to help you understand your font usage. You remain fully responsible for verifying proper licencing. Results should be independently verified before making any legal or business decisions regarding font licencing.
Search detailed guidance about website scans, reports, plans and Enterprise features.
Enter a website URL such as example.com or https://example.com in the scanner form. FontReport adds https:// when needed. Starter scans can include up to 250 pages and Agency scans up to 500 pages. Enterprise accounts can have custom limits and additional scan types.
For each font family found, you'll see:
FontReport can analyse publicly accessible content, but it cannot sign in to pages behind login walls, passwords, paywalls or other interactive authentication. Enterprise customers can allowlist FontReport's static crawler IPs through a firewall or WAF when the underlying site is public but network-restricted. This does not provide access to authenticated content.
Before scanning, FontReport checks your site's robots.txt file (the standard method for websites to communicate crawling preferences to bots). If your robots.txt file contains warnings about automated access or blocks common crawlers, FontReport respects this as a signal that automated crawling is not desired and will not proceed with the scan.
Solution for site owners: If you own the domain and want FontReport to scan it, you have two options:
User-agent: FontReport
Allow: /
Standard scans inspect HTML, CSS, JavaScript and accessible font files. Enterprise browser rendering adds coverage for JavaScript-injected, SPA and scroll-loaded fonts. Fonts can still be missed when they are:
Review the coverage and error notices in the report before treating a result as a complete inventory.
FontReport extracts licensing metadata directly from font files where available, but this information should be verified independently. Font licensing can be complex, and the metadata may be incomplete or outdated. Always consult the original font license agreements for definitive licensing terms.
This indicates FontReport detected fonts from providers that typically require paid licenses (like Adobe Fonts, MyFonts, or Hoefler Cloud). While you might have proper licenses, these fonts are flagged for your review to help you verify licensing status. Google Fonts are marked as safe because they're free for all uses.
This action appears when the name used in your CSS (font-family) does not match the embedded name inside the font file metadata (TypographicFamily/PostScriptName).
Why this matters: it can indicate a font has been renamed. For example, a file named bodyfont.otf declared as font-family: 'bodyfont' may still contain metadata for a known commercial family.
It can also reveal questionable downloads. If a font is presented as "free" but its metadata identifies a commercial family, that is a strong signal to verify the source and license terms.
Important: this is a review flag, not automatic proof of misuse. Legitimate setups can still trigger it due to naming conventions, packaging, style/variant naming, or theme/plugin bundling.
FontReport flags these cases so you can manually check licensing of those specific fonts.
Some font vendors have granular licensing that requires separate licenses depending on how you use the font. While a standard web or desktop license may cover general use on your website, using that same font in your company logo, brand identity, or product packaging often requires a separate "logo license" or "trademark license."
Why this matters: If your website uses a font that requires logo licensing and that same font appears in your logo, favicon, or brand materials, you may need an additional license even if you've properly licensed the web usage.
FontReport flags fonts from vendors known to require logo licensing, but cannot automatically detect whether you're using the font in a logo. It's your responsibility to verify whether your actual usage complies with each vendor's specific terms. Check the licensing page for each flagged vendor to understand their requirements.
Google Fonts are open-source and free to use, but loading them from Google's servers sends a visitor's request and IP address to Google. Whether that is appropriate depends on your jurisdiction, privacy notices, consent approach and other circumstances.
A 2022 decision by the Regional Court of Munich found that a particular site's remote use of Google Fonts infringed the claimant's privacy rights. That decision is useful context, but it should not be treated as a universal legal conclusion for every website.
Common approaches include:
Read Google Fonts' current privacy explanation and obtain legal advice for your circumstances. FontReport provides a technical privacy hint, not a legal determination.
The "via proxy" indicator appears when the website's server rejected our initial connection request, requiring us to route the scan through a proxy server instead. This is a technical workaround that allows the scan to complete successfully.
Why this happens: Some web servers have security measures that block requests from data centers or automated tools. When this occurs, FontReport automatically switches to a proxy server to complete your scan.
Does this affect my results? The same detection process is used, so proxy routing does not itself reduce scan quality. A proxy scan can take longer, and geography, WAF behaviour or personalised content can still affect what the site returns. Check report coverage and connection errors when completeness matters.
Possibly unused weights are font weights or styles, such as Bold, Light or Italic, that FontReport found on the website but could not find being used. For example, if weights 300, 400, 700 and 900 are loaded but only 400 and 700 appear in the scanned pages and styles, 300 and 900 may be flagged for review.
Why this matters: Each unused font variant adds unnecessary file size to your pages, increasing load times and bandwidth usage. Removing unused variants can improve website performance.
Before removing fonts:
How to optimise: Use the per-weight breakdown and Source Inspector to verify the evidence, then test any removal in a safe environment.
User Fonts are fonts declared in your CSS without corresponding font files on your server. These fonts will only display if visitors have them installed on their device, otherwise the browser falls back to the next font in your CSS font stack.
This isn't a licensing concern, but FontReport specifically flags User Fonts when they are listed as the primary (first) font in your CSS declarations. This is important because:
Important note: Some fonts may appear as "User Fonts" if an external CSS file containing @font-face declarations could not be accessed during scanning. If you see unexpected User Font entries, check if any external font services (like Adobe Fonts or custom font CDNs) appear as "Connection failed" in your report.
To ensure consistent typography for all visitors, replace primary User Fonts with properly loaded web fonts that you have licensed.
These errors typically mean:
This appears when FontReport finds more pages than the limit selected for that scan. The crawler discovered additional internal pages but stopped at the requested budget. Run another scan with a higher page limit, or use cumulative Enterprise scanning for a very large site.
Scan speed depends on:
Large or slow-responding websites may take several minutes. If scans consistently time out, try reducing the page limit or scanning during off-peak hours.
This means FontReport detected font references pointing to an external domain that was unable to accessed during scanning. Common reasons include:
These fonts may still work for your website visitors, but you should manually verify the licensing status with the external domain. Check your font service subscriptions and ensure they're active for your domain.
Websites often reference fonts in several ways:
FontReport reports the references discovered within the selected pages and accessible assets. Coverage limits, blocked assets, third-party embeds and deliberately suppressed advertising or widget domains can affect what appears, so review the report's coverage notices.
Primary fonts are listed first in a CSS font-family stack and are the fonts your visitors will most likely see. For example, in font-family: "Helvetica", Arial, sans-serif, Helvetica is the primary font.
Fallback fonts are backup fonts listed after the primary font. They're only used if the primary font fails to load or isn't available on the visitor's device. In the example above, Arial and sans-serif are fallback fonts.
Both primary and fallback fonts may require licenses if they're commercial fonts that you're hosting as font files on your server or embedding from third-party services.
A duplicate font file finding means the same filename was discovered at multiple URLs. It is a strong cleanup signal, but it does not by itself prove the file contents are identical. Common causes include:
Duplicate Source Files are different: that finding uses a content hash to identify CSS or JavaScript files whose contents are identical even though their URLs differ.
What to do: Inspect the referenced sources, confirm which copies are genuinely redundant, choose the source to retain and test the site after any removal.
This indicates that font files were found but didn't contain complete vendor information (foundry name, copyright, license details). This is common with:
FontReport identifies font providers by analyzing the source URLs and domains where fonts are hosted:
Classification combines source URL patterns, CSS declarations, recognised provider metadata and metadata extracted from accessible font files. Treat the provider label as technical evidence to verify, not a licence determination.
FontMonitor provides ongoing font compliance monitoring rather than a single snapshot. Enterprise accounts can use:
The best option depends on the size of your website, how often it changes and whether you also need to monitor documents or app releases.
FontMonitor compares each new scan with the previous one. It can alert you when fonts are added or removed, when font files, sources or weights change, and when a recorded licence renewal date is approaching or overdue.
Cumulative scanning is designed for websites that are too large to scan in one go. FontReport scans up to 5000 pages at a time, saves the results, then continues in further batches until all pages it can find have been scanned. Custom limits are available by agreement.
Very large websites sometimes split their page list across many sitemap files. FontReport can check up to 5000 of these files. If the website has more, the report will clearly say that it may not cover the whole site.
Interim checks are useful for websites that publish new pages frequently. Between full scans, FontReport checks the website's sitemap for newly added pages and scans only those pages for fonts. Existing pages are checked again during the next full scan.
FontReport checks up to 500 child sitemaps during an interim check. A child sitemap is simply one of the smaller sitemap files listed inside a website's main sitemap. Most websites are well below this limit. If a very large website exceeds it, the report will tell you that some new pages may not have been checked.
An interim check is an early-warning check for new content, not a replacement for regular full scans.
A Watched Folder regularly checks a shared Google Drive folder for new or updated PDFs and supported app packages. When a file changes, FontReport scans it and alerts you if it finds fonts that need review.
Checks can run every 1, 4, 12 or 24 hours. Files that have not changed do not need to be scanned again. A folder can contain up to 10,000 PDFs under the current limit.
If the folder is deleted or is no longer shared with FontReport, monitoring pauses until access is restored.
Enterprise scans can open JavaScript-driven websites in Chromium, the browser engine used by Google Chrome. FontReport loads the page, follows internal links through Chromium within the scan's page limit, and checks fonts that appear after scrolling.
This helps find fonts that are added by JavaScript or loaded as visitors move through a modern website or web application.
Yes. For Enterprise customers, our crawler IP addresses can be provided on request so they can be allowlisted in your firewall or WAF.
This helps when a public website blocks automated visitors. It does not allow FontReport to sign in to password-protected pages or bypass application authentication. Contact us to request the crawler details.
You do not connect your personal Google account to FontReport. FontReport uses its own read-only Google account to inspect folders explicitly shared with it.
FontReport follows shared subfolders and scans supported PDFs. When app scanning is enabled for the account, it can also inspect supported app packages. Google Docs, Sheets, Slides, images and other unsupported file types are ignored.
App packages need to be uploaded as the original packaged file or a supported ZIP. Unpacked app folders are not supported.
PDF scanning can inspect PDFs linked from a website and PDFs stored in an authorised Google Drive folder.
Up to 500 PDFs can be scanned from a shared folder in one run. Each PDF can be up to 75 MB, with a combined limit of 2 GB across all files in that scan. PDFs of up to 250 pages are supported. Enterprise limits can be customised.
FontReport looks for fonts embedded inside each PDF. PDFs where all text has been rasterised are listed as PDFs without fonts in your report.
fsType is a setting stored inside a font file that describes how the font may be embedded in documents:
FontReport warns when fsType 2 indicates restricted embedding and there is no Preview and Print or Editable permission. If fsType 2 is combined with fsType 4 or 8, FontReport explains the setting but does not treat the font as completely blocked because preview, printing or editing is permitted.
FontReport also warns when a subset is embedded despite a No Subsetting flag, or font data is embedded despite a Bitmap Embedding Only flag. These are review flags, not a final legal conclusion.
A subset contains only the characters that are actually used in the PDF. This is normal and FontReport only warns about it when the font's settings say that subsetting is not allowed.
A placed-object notice means the font was found inside artwork such as a logo, chart, advertisement or imported design file. This helps you identify where the font came from so you can check the relevant licence.
FontReport can scan IPA, APK, AAB, XAPK, APKS, APKM, .app.zip and supported app ZIP files.
Coverage is strongest for native iOS, macOS and Android apps, Flutter and React Native. Xamarin or MAUI, Cordova or Capacitor and Unity are also supported in part. Some game engines and specialised frameworks package fonts in formats that cannot be fully read. If this happens, the report will tell you that additional fonts may be present.
FontReport checks the font files found inside an app package and highlights:
Recognised Google Fonts and SIL Open Font Licence fonts are identified separately. Fonts downloaded from a provider at runtime are also listed, even when the font file is not bundled inside the app.
A possibly unused finding is not a recommendation to delete the font. Your developer should confirm whether it is loaded dynamically before making changes.
App Scan credits are separate from website scan credits. One credit is normally used when a new app or app version is scanned for the first time. Scanning the same app version again does not normally use another credit, while a new version may.
Up to 1,000 app packages can be scanned from a shared folder in one run. Each package can be up to 1 GB, with a combined limit of 1.5 GB across all app packages in that scan. Enterprise limits can be customised.
For the best results, upload the final packaged app file rather than an unpacked folder.
Free scans are limited to:
Paid scan packs include:
Scan packs are paid upgrades that unlock enhanced features:
Starter includes 10 scans and Agency includes 50 scans. Credits are valid for 30 days from purchase and work through an access key sent to your email.
Access keys are unique codes that activate your scan pack features:
Keep your access key private. If it is lost, the email recovery flow can replace it and invalidate the old key.
Use the forgotten access key form and enter the purchase email address. FontReport emails a time-limited recovery link, which must be completed in the same browser that requested it.
Completing recovery creates a new access key, invalidates the old one and signs the browser in. If the automated flow does not work, contact us.
When you purchase a new scan pack, active unused credits are combined with the new credits and the expiry date extends to 30 days from the new purchase date.
Example: If you have 20 active credits and purchase an Agency pack with 50 credits, you will have 70 credits, all expiring 30 days from the new purchase.
Important: If your credits have already expired when you purchase a new pack, the expired credits are removed. Only active, non-expired credits are extended when you top up.
The Agency Scan Pack is designed for agencies, consultants, and teams managing multiple client websites. It includes:
Perfect for auditing client portfolios or scanning multiple websites efficiently.
Batch scanning (Agency Pack only) lets you scan multiple websites at once:
Each URL counts as one scan from your credit balance. You can scan up to your available credits at once.
There is no separate 100-site batch limit. Batch mode queues URLs up to the number of active credits available. Purchase another Agency pack to add credits, or contact us about Enterprise when you need ongoing monitoring, team access or very large portfolio coverage.
If Agency benefits have expired, purchasing a new Agency pack restores them.
Print-friendly reports provide a clean, professional PDF-style layout optimized for printing or saving. They include all font information, metadata, and licensing indicators in an easy-to-read format without web navigation elements.
The scan history dashboard shows all your previous scans in an organized table with details like scan date, website URL, number of pages scanned, and font scan results.

Your privacy is protected:
Free scans: Results are stored for up to 7 days for reference, then automatically deleted.
Starter: Results are stored for up to 30 days.
Agency: Results are stored for up to 90 days.
Enterprise: Results, including FontMonitor history, are normally stored for up to 365 days. A customer agreement or an individually adjusted report may specify a different period.
Free, Starter and Agency report links are unlisted but should be treated as shareable URLs. Anyone who receives the link may be able to open it while the report remains available.
Enterprise reports are private and protected by account access and email 2FA by default. An authorised Enterprise owner can explicitly enable a shareable public link for a report and turn sharing off again later.
The Font Inventory gives your team one place to record which fonts have been reviewed. You can mark a font as Compliant or Ignored, add notes about the licence and record a renewal date.
A decision can apply to one website, Google Drive folder or app package, or across the whole account. Renewal reminders help your team review licences before they expire, and the saved status can be included in Enterprise exports.
An Enterprise account can invite up to 10 team members in any mix of co-owners and members.
Invitations and access are associated with each person's email address, so users should not share one access key across a team.
Enterprise reports are private by default. Account access uses the Enterprise access key together with email 2FA, and a verified browser can be trusted for a limited period.
An authorised owner can enable a public share link for an individual report when an external recipient needs access, then disable that link later. Internal report notes and account-management information are not intended to be exposed through public sharing.
Enterprise plans can include different allowances for:
These are shown separately in the dashboard so you can see exactly what is included in your plan and what is currently in use.
This is a common but risky assumption. Many website owners believe that fonts included with purchased themes or plugins are properly licensed, but this isn't always the case. Plugin and theme developers sometimes:
Even if you paid for the theme or plugin, this doesn't automatically grant you font licensing rights. The theme license typically covers the code and design, not necessarily the fonts. It's worth checking with the theme/plugin developer about font licensing and consider replacing questionable fonts with verified alternatives like Google Fonts.
You can cross-check results by:
These tools help verify the technical evidence. They do not replace the original licence agreement or legal advice.
Get detailed insights into your website's font usage and identify fonts that may need licensing verification in just minutes.