About FontReport

What is FontReport?

FontReport analyses fonts across websites, PDFs and supported app packages, identifies their sources, and provides evidence to help assess potential licencing considerations. It is built for designers, developers, agencies and enterprise teams that need an accurate, repeatable view of font usage.

How FontReport works

FontReport performs detailed technical analysis by:

  1. Crawling multiple pages to discover all font references in CSS files, JavaScript and external stylesheets
  2. Extracting font metadata directly from font files to provide licencing and vendor information where available
  3. Identifying system fonts and fallback declarations in CSS files
  4. Categorising fonts by provider (Google Fonts, Adobe Fonts, self-hosted, etc.)
  5. Supporting Enterprise workflows for browser-rendered sites, PDFs, shared Google Drive folders, app packages and ongoing monitoring

Why use FontReport

Comprehensive analysis

Multi-page scanning with CSS and JavaScript file analysis, direct font metadata extraction, and categorization of fonts by type (commercial, free and system fonts). Shows exactly which files and pages reference each font across your website.

Compliance risks

Font foundries now have sophisticated tools to detect unlicensed usage across the web. What was once rarely enforced has become a real business risk, making proactive font auditing essential for website owners.

Ease of use

No more manually digging through CSS files or asking developers what fonts are installed. Automatically discovers fonts you didn't know existed - from third party theme/plugin fonts to old fonts hiding in your codebase.

The font licencing challenge

Font licencing has always been complex, but the stakes have never been higher. Traditional methods for tracking font usage across websites are limited and time-consuming.

Current approaches and their limitations

  1. Manual Inspection: Checking CSS files and font folders manually is time-consuming, error-prone and doesn't scale across multiple pages or complex websites
  2. Browser Developer Tools: Only shows fonts on individual pages you're viewing, missing fonts used elsewhere on the site and providing no licencing information
  3. Spreadsheet Tracking: Requires manual updates and often falls out of sync with actual website implementations
  4. Asking Developers: Team members may not remember all font sources, especially on sites built over time or inherited from previous developers
  5. Limited web scanners: Most existing tools only analyze single pages or individual elements, lacking comprehensive site-wide analysis and font metadata extraction needed for licensing compliance

Why this matters now

Font foundries and licensing companies now have sophisticated tools for discovering unlicensed font usage across the web, making it easier than ever for rights holders to identify potential licensing violations and pursue legal action. What was once rarely enforced has become a legitimate business concern that requires proactive management.

Common ways businesses get caught out

  • Developer oversight: Developers embed fonts provided by designers without understanding licensing requirements or restrictions
  • Web licensing gaps: Many desktop font licenses prohibit web use unless specific web font licenses are purchased separately
  • Commercial use restrictions: Free fonts often prohibit commercial use, requiring paid licenses for business websites
  • Expired subscriptions: Font service licenses may have expired where auto-renewal failed or wasn't available

FontReport addresses this gap by providing comprehensive, automated font discovery across entire websites, giving you the visibility needed to identify fonts that may require licence verification and to avoid potential legal disputes.

FontReport vs Other Font Analysis Tools

Feature
FontReport
Other Tools
Free Trial
2 preview scans/day
(1 page each)
Varies by tool
Entire site crawling
✅ Up to 250 pages per site (500 with Agency Pack)
❌ Typically single pages or elements
Batch scanning
✅ Queue multiple sites up to your available Agency credits
❌ Single site scanning only
Advanced font detection
✅ External files, JS, metadata extraction and Enterprise browser rendering
❌ Limited metadata extraction
Licensing hints
✅ Detects likely commercial fonts
❌ None
Font health checks
✅ Duplicate fonts, renamed fonts, unused weights, GDPR hints
❌ None
Report export
✅ Print-friendly reports; Agency and Enterprise Excel exports
❌ Limited or no export options
Dashboard & history
✅ Scan history dashboard
❌ Limited or no history
Login required
✅ Access key; Enterprise accounts add email 2FA
Varies by tool

Things to know

FontReport scans website code and styles to identify fonts across the pages included in a scan. Enterprise options extend coverage to browser-rendered content, PDFs, shared Google Drive folders and supported app packages. Some scenarios still need manual checks:

  • Content behind authentication or paywalls
  • Unsupported document formats such as Word or PowerPoint files
  • Dynamic content outside the pages and interactions covered by Enterprise browser rendering
  • Fonts within third-party widgets or restricted access
  • Remote app fonts or proprietary package containers that cannot be inspected

Important: FontReport is an analysis tool that provides information to help you understand your font usage. You remain fully responsible for verifying proper licencing. Results should be independently verified before making any legal or business decisions regarding font licencing.

Frequently Asked Questions

Search detailed guidance about website scans, reports, plans and Enterprise features.

Getting Started

Enter a website URL such as example.com or https://example.com in the scanner form. FontReport adds https:// when needed. Starter scans can include up to 250 pages and Agency scans up to 500 pages. Enterprise accounts can have custom limits and additional scan types.

For each font family found, you'll see:

  • Font variants (weights, styles) detected
  • Source provider (Google Fonts, Adobe Fonts, self-hosted, etc.)
  • Individual font files with direct links
  • Pages where the font is used
  • Vendor metadata (foundry, copyright, license information) for self-hosted fonts
  • Indicators highlighting fonts that may need license verification

FontReport can analyse publicly accessible content, but it cannot sign in to pages behind login walls, passwords, paywalls or other interactive authentication. Enterprise customers can allowlist FontReport's static crawler IPs through a firewall or WAF when the underlying site is public but network-restricted. This does not provide access to authenticated content.

Before scanning, FontReport checks your site's robots.txt file (the standard method for websites to communicate crawling preferences to bots). If your robots.txt file contains warnings about automated access or blocks common crawlers, FontReport respects this as a signal that automated crawling is not desired and will not proceed with the scan.

Solution for site owners: If you own the domain and want FontReport to scan it, you have two options:

  1. Add FontReport to your robots.txt (recommended): Add these lines to allow FontReport while keeping other restrictions:
    User-agent: FontReport
    Allow: /
  2. Request whitelisting: Contact us at hello@fontreport.com with your domain name, and we'll add it to our authorized list.

Scan Results and Accuracy

Standard scans inspect HTML, CSS, JavaScript and accessible font files. Enterprise browser rendering adds coverage for JavaScript-injected, SPA and scroll-loaded fonts. Fonts can still be missed when they are:

  • Loaded only after interactions or pages that the Enterprise browser scan does not reach
  • Embedded in unsupported downloadable files such as Word or PowerPoint documents
  • Located on pages not included in the scan (if you limited the page count)
  • Loaded from third-party widgets or embedded content with restricted access
  • Unavailable because of authentication, WAF rules, rate limits or asset connection failures

Review the coverage and error notices in the report before treating a result as a complete inventory.

FontReport extracts licensing metadata directly from font files where available, but this information should be verified independently. Font licensing can be complex, and the metadata may be incomplete or outdated. Always consult the original font license agreements for definitive licensing terms.

This indicates FontReport detected fonts from providers that typically require paid licenses (like Adobe Fonts, MyFonts, or Hoefler Cloud). While you might have proper licenses, these fonts are flagged for your review to help you verify licensing status. Google Fonts are marked as safe because they're free for all uses.

This action appears when the name used in your CSS (font-family) does not match the embedded name inside the font file metadata (TypographicFamily/PostScriptName).

Why this matters: it can indicate a font has been renamed. For example, a file named bodyfont.otf declared as font-family: 'bodyfont' may still contain metadata for a known commercial family.

It can also reveal questionable downloads. If a font is presented as "free" but its metadata identifies a commercial family, that is a strong signal to verify the source and license terms.

Important: this is a review flag, not automatic proof of misuse. Legitimate setups can still trigger it due to naming conventions, packaging, style/variant naming, or theme/plugin bundling.

FontReport flags these cases so you can manually check licensing of those specific fonts.

Some font vendors have granular licensing that requires separate licenses depending on how you use the font. While a standard web or desktop license may cover general use on your website, using that same font in your company logo, brand identity, or product packaging often requires a separate "logo license" or "trademark license."

Why this matters: If your website uses a font that requires logo licensing and that same font appears in your logo, favicon, or brand materials, you may need an additional license even if you've properly licensed the web usage.

FontReport flags fonts from vendors known to require logo licensing, but cannot automatically detect whether you're using the font in a logo. It's your responsibility to verify whether your actual usage complies with each vendor's specific terms. Check the licensing page for each flagged vendor to understand their requirements.

Google Fonts are open-source and free to use, but loading them from Google's servers sends a visitor's request and IP address to Google. Whether that is appropriate depends on your jurisdiction, privacy notices, consent approach and other circumstances.

A 2022 decision by the Regional Court of Munich found that a particular site's remote use of Google Fonts infringed the claimant's privacy rights. That decision is useful context, but it should not be treated as a universal legal conclusion for every website.

Common approaches include:

  • Self-hosting: Serve the open-source font files from infrastructure you control
  • Consent management: Delay remote font requests until the required consent has been obtained
  • Another provider: Assess a provider whose location and data practices meet your requirements

Read Google Fonts' current privacy explanation and obtain legal advice for your circumstances. FontReport provides a technical privacy hint, not a legal determination.

The "via proxy" indicator appears when the website's server rejected our initial connection request, requiring us to route the scan through a proxy server instead. This is a technical workaround that allows the scan to complete successfully.

Why this happens: Some web servers have security measures that block requests from data centers or automated tools. When this occurs, FontReport automatically switches to a proxy server to complete your scan.

Does this affect my results? The same detection process is used, so proxy routing does not itself reduce scan quality. A proxy scan can take longer, and geography, WAF behaviour or personalised content can still affect what the site returns. Check report coverage and connection errors when completeness matters.

Possibly unused weights are font weights or styles, such as Bold, Light or Italic, that FontReport found on the website but could not find being used. For example, if weights 300, 400, 700 and 900 are loaded but only 400 and 700 appear in the scanned pages and styles, 300 and 900 may be flagged for review.

Why this matters: Each unused font variant adds unnecessary file size to your pages, increasing load times and bandwidth usage. Removing unused variants can improve website performance.

Before removing fonts:

  • The result is evidence-based, not proof that a weight is unused everywhere
  • Dynamic JavaScript, complex inheritance, unscanned pages and inaccessible assets can hide usage
  • Always test your website thoroughly after removing any font files to ensure nothing breaks visually

How to optimise: Use the per-weight breakdown and Source Inspector to verify the evidence, then test any removal in a safe environment.

User Fonts are fonts declared in your CSS without corresponding font files on your server. These fonts will only display if visitors have them installed on their device, otherwise the browser falls back to the next font in your CSS font stack.

This isn't a licensing concern, but FontReport specifically flags User Fonts when they are listed as the primary (first) font in your CSS declarations. This is important because:

  • Primary User Fonts are non-system fonts that are unlikely to be installed on most visitors' devices
  • Most of your visitors will see your fallback fonts instead of your intended typography
  • This creates an inconsistent design experience across different users
  • Fallback User Fonts (listed after your primary font) are less concerning since they're only used if other fonts fail

Important note: Some fonts may appear as "User Fonts" if an external CSS file containing @font-face declarations could not be accessed during scanning. If you see unexpected User Font entries, check if any external font services (like Adobe Fonts or custom font CDNs) appear as "Connection failed" in your report.

To ensure consistent typography for all visitors, replace primary User Fonts with properly loaded web fonts that you have licensed.

Technical Issues

These errors typically mean:

  • The domain no longer exists or has DNS issues
  • The website is temporarily down or blocking automated requests
  • The domain might be on our security blocklist (check URLhaus database to see if your domain appears on security feeds)
  • There might be network connectivity issues

This appears when FontReport finds more pages than the limit selected for that scan. The crawler discovered additional internal pages but stopped at the requested budget. Run another scan with a higher page limit, or use cumulative Enterprise scanning for a very large site.

Scan speed depends on:

  • Website response time and server performance
  • Number of pages being scanned
  • Amount of CSS and JavaScript to process
  • Network conditions

Large or slow-responding websites may take several minutes. If scans consistently time out, try reducing the page limit or scanning during off-peak hours.

This means FontReport detected font references pointing to an external domain that was unable to accessed during scanning. Common reasons include:

  • The font service requires authentication or referrer validation
  • The domain blocks automated requests for security
  • Rate limiting or geographic restrictions
  • The font service may have changed its access policies
  • The domain may be temporarily down

These fonts may still work for your website visitors, but you should manually verify the licensing status with the external domain. Check your font service subscriptions and ensure they're active for your domain.

Font Detection and Analysis

  • Google Fonts: Open-source fonts identified from Google's CDN or recognised Google font metadata.
  • Self-Hosted: Font files served from the website's own domain or CDN. They may be commercial, open-source or customer-owned, so verify the actual licence and source.
  • Third-Party: Fonts from commercial or external services, which may require a subscription or licence.
  • System Fonts: Default fonts available on user devices (Arial, Times New Roman, etc.).

Websites often reference fonts in several ways:

  • CSS font stacks with multiple fallback fonts
  • Unused CSS that still contains font references
  • Third-party plugins or widgets that load their own fonts
  • System fonts defined as fallbacks even if custom fonts load successfully

FontReport reports the references discovered within the selected pages and accessible assets. Coverage limits, blocked assets, third-party embeds and deliberately suppressed advertising or widget domains can affect what appears, so review the report's coverage notices.

Primary fonts are listed first in a CSS font-family stack and are the fonts your visitors will most likely see. For example, in font-family: "Helvetica", Arial, sans-serif, Helvetica is the primary font.

Fallback fonts are backup fonts listed after the primary font. They're only used if the primary font fails to load or isn't available on the visitor's device. In the example above, Arial and sans-serif are fallback fonts.

Both primary and fallback fonts may require licenses if they're commercial fonts that you're hosting as font files on your server or embedding from third-party services.

A duplicate font file finding means the same filename was discovered at multiple URLs. It is a strong cleanup signal, but it does not by itself prove the file contents are identical. Common causes include:

  • A font is both self-hosted on your server AND loaded from a CDN or third-party service
  • Multiple plugins or themes each load their own copy of the same font
  • A font is loaded from both Google Fonts and a local file
  • Different versions of the same font are loaded from multiple providers

Duplicate Source Files are different: that finding uses a content hash to identify CSS or JavaScript files whose contents are identical even though their URLs differ.

What to do: Inspect the referenced sources, confirm which copies are genuinely redundant, choose the source to retain and test the site after any removal.

This indicates that font files were found but didn't contain complete vendor information (foundry name, copyright, license details). This is common with:

  • Older font files that lack modern metadata
  • Fonts that have been processed or optimized in ways that strip metadata
  • Free or open-source fonts with minimal embedded information

FontReport identifies font providers by analyzing the source URLs and domains where fonts are hosted:

  • Google Fonts: Fonts served from fonts.googleapis.com or fonts.gstatic.com domains
  • Adobe Fonts: Fonts from typekit.net, use.typekit.net, p.typekit.net, or fonts.adobe.com domains
  • MyFonts/Monotype: Fonts from myfonts.net, hello.myfonts.net, fast.fonts.net, or Monotype-related domains
  • Lineto: Fonts from lineto.com or cdn.lineto.com domains
  • Hoefler Cloud: Fonts from typography.com or Hoefler-related domains
  • CDNFonts: Fonts from cdnfonts.com domains
  • Fontsource: Open-source fonts from cdn.jsdelivr.net/fontsource or fontsource.org domains
  • Bunny Fonts: Privacy-focused free fonts from fonts.bunny.net domain
  • Third-Party: Font files most likely hosted by another external provider
  • Self-Hosted: Font files hosted on any domain not matching the above commercial providers
  • System Fonts: Fonts from FontReport's predefined list of standard operating system fonts (Arial, Times New Roman, Helvetica, etc.) that are typically pre-installed on user devices
  • User Fonts: Fonts declared in CSS but not in the system font list and with no corresponding font files found – these require the specific font to be installed on the user's device

Classification combines source URL patterns, CSS declarations, recognised provider metadata and metadata extracted from accessible font files. Treat the provider label as technical evidence to verify, not a licence determination.

Enterprise Monitoring

FontMonitor provides ongoing font compliance monitoring rather than a single snapshot. Enterprise accounts can use:

  • Scheduled scans: Scan a website regularly and receive alerts when its fonts change.
  • Cumulative scans: Scan very large websites in smaller batches until the full site has been covered.
  • Interim checks: Check newly published pages between full website scans.
  • Watched Folders: Check a shared Google Drive folder for new or updated PDFs and app packages.

The best option depends on the size of your website, how often it changes and whether you also need to monitor documents or app releases.

FontMonitor compares each new scan with the previous one. It can alert you when fonts are added or removed, when font files, sources or weights change, and when a recorded licence renewal date is approaching or overdue.

Cumulative scanning is designed for websites that are too large to scan in one go. FontReport scans up to 5000 pages at a time, saves the results, then continues in further batches until all pages it can find have been scanned. Custom limits are available by agreement.

Very large websites sometimes split their page list across many sitemap files. FontReport can check up to 5000 of these files. If the website has more, the report will clearly say that it may not cover the whole site.

Interim checks are useful for websites that publish new pages frequently. Between full scans, FontReport checks the website's sitemap for newly added pages and scans only those pages for fonts. Existing pages are checked again during the next full scan.

FontReport checks up to 500 child sitemaps during an interim check. A child sitemap is simply one of the smaller sitemap files listed inside a website's main sitemap. Most websites are well below this limit. If a very large website exceeds it, the report will tell you that some new pages may not have been checked.

An interim check is an early-warning check for new content, not a replacement for regular full scans.

A Watched Folder regularly checks a shared Google Drive folder for new or updated PDFs and supported app packages. When a file changes, FontReport scans it and alerts you if it finds fonts that need review.

Checks can run every 1, 4, 12 or 24 hours. Files that have not changed do not need to be scanned again. A folder can contain up to 10,000 PDFs under the current limit.

If the folder is deleted or is no longer shared with FontReport, monitoring pauses until access is restored.

Enterprise scans can open JavaScript-driven websites in Chromium, the browser engine used by Google Chrome. FontReport loads the page, follows internal links through Chromium within the scan's page limit, and checks fonts that appear after scrolling.

This helps find fonts that are added by JavaScript or loaded as visitors move through a modern website or web application.

Yes. For Enterprise customers, our crawler IP addresses can be provided on request so they can be allowlisted in your firewall or WAF.

This helps when a public website blocks automated visitors. It does not allow FontReport to sign in to password-protected pages or bypass application authentication. Contact us to request the crawler details.

Google Drive, PDF and App Scanning

  1. In Google Drive, share the folder with hello@fontreport.com and give it permission to view the files.
  2. Copy the Google Drive folder URL.
  3. Paste that URL into the normal FontReport scan form and start the scan.

You do not connect your personal Google account to FontReport. FontReport uses its own read-only Google account to inspect folders explicitly shared with it.

FontReport follows shared subfolders and scans supported PDFs. When app scanning is enabled for the account, it can also inspect supported app packages. Google Docs, Sheets, Slides, images and other unsupported file types are ignored.

App packages need to be uploaded as the original packaged file or a supported ZIP. Unpacked app folders are not supported.

PDF scanning can inspect PDFs linked from a website and PDFs stored in an authorised Google Drive folder.

Up to 500 PDFs can be scanned from a shared folder in one run. Each PDF can be up to 75 MB, with a combined limit of 2 GB across all files in that scan. PDFs of up to 250 pages are supported. Enterprise limits can be customised.

FontReport looks for fonts embedded inside each PDF. PDFs where all text has been rasterised are listed as PDFs without fonts in your report.

fsType is a setting stored inside a font file that describes how the font may be embedded in documents:

  • 0: Installable embedding.
  • 2: Restricted embedding.
  • 4: Preview and Print embedding.
  • 8: Editable embedding.

FontReport warns when fsType 2 indicates restricted embedding and there is no Preview and Print or Editable permission. If fsType 2 is combined with fsType 4 or 8, FontReport explains the setting but does not treat the font as completely blocked because preview, printing or editing is permitted.

FontReport also warns when a subset is embedded despite a No Subsetting flag, or font data is embedded despite a Bitmap Embedding Only flag. These are review flags, not a final legal conclusion.

A subset contains only the characters that are actually used in the PDF. This is normal and FontReport only warns about it when the font's settings say that subsetting is not allowed.

A placed-object notice means the font was found inside artwork such as a logo, chart, advertisement or imported design file. This helps you identify where the font came from so you can check the relevant licence.

FontReport can scan IPA, APK, AAB, XAPK, APKS, APKM, .app.zip and supported app ZIP files.

Coverage is strongest for native iOS, macOS and Android apps, Flutter and React Native. Xamarin or MAUI, Cordova or Capacitor and Unity are also supported in part. Some game engines and specialised frameworks package fonts in formats that cannot be fully read. If this happens, the report will tell you that additional fonts may be present.

FontReport checks the font files found inside an app package and highlights:

  • Restricted embedding settings: Fonts whose embedded settings indicate that distribution or embedding should be reviewed first.
  • Fonts requiring licence review: Copyright or licence details are present, but FontReport cannot confirm that they cover distribution inside an app.
  • Missing licence information: The font file does not contain enough copyright, vendor or licence information to classify it.
  • Possibly unused fonts: The font is included in the app package but FontReport did not find a registration or reference showing where it is used.
  • Bitmap or SDF text: Text has been converted into images or a font atlas, so the licence of the original source font may still matter.
  • Incomplete coverage: Part of the app is encrypted or stored in a format FontReport cannot fully read, so additional fonts may be present.

Recognised Google Fonts and SIL Open Font Licence fonts are identified separately. Fonts downloaded from a provider at runtime are also listed, even when the font file is not bundled inside the app.

A possibly unused finding is not a recommendation to delete the font. Your developer should confirm whether it is loaded dynamically before making changes.

App Scan credits are separate from website scan credits. One credit is normally used when a new app or app version is scanned for the first time. Scanning the same app version again does not normally use another credit, while a new version may.

Up to 1,000 app packages can be scanned from a shared folder in one run. Each package can be up to 500 MB, with a combined limit of 1.5 GB across all app packages in that scan. Enterprise limits can be customised.

For the best results, upload the final packaged app file rather than an unpacked folder.

Scan Packs & Payment

Free scans are limited to:

  • 1 page maximum per scan
  • 2 scans per day
  • Font preview - you'll see a representative sample of detected fonts only (roughly half of all found fonts)

Paid scan packs include:

  • Up to 250 pages per Starter scan and 500 with Agency
  • Complete font inventory - all detected fonts
  • File paths and CSS references for debugging and compliance
  • Page locations showing exactly where each font is used
  • Print-friendly reports for paid scans, with Excel export on Agency and Enterprise
  • Scan history dashboard for 30 days on Starter, 90 days on Agency and 365 days on Enterprise

Scan packs are paid upgrades that unlock enhanced features:

  • More pages: Scan up to 250 pages with Starter or 500 with Agency instead of the free 1-page preview
  • Advanced information: Font files, stylesheet references and pages found
  • More scans: Up to 20 scans per hour or 100 per day; Agency allows 100 per hour or 500 per day
  • Print reports: Clean, print-friendly PDF-style formatting (view example)
  • Excel file export: Agency and Enterprise reports can be saved as Excel workbooks for record-keeping and analysis
  • Scan history: Access reports for 30 days on Starter or 90 days on Agency (view example)
  • Batch scanning: (Agency Pack only) Scan multiple websites at once
  • Faster scanning: Higher rate limits for quicker results

Starter includes 10 scans and Agency includes 50 scans. Credits are valid for 30 days from purchase and work through an access key sent to your email.

Access keys are unique codes that activate your scan pack features:

  1. Purchase a scan pack and receive your access key via email
  2. Enter the key using the "Enter Access Key" button on the homepage
  3. Use the same key to access your scan history dashboard

Keep your access key private. If it is lost, the email recovery flow can replace it and invalidate the old key.

Use the forgotten access key form and enter the purchase email address. FontReport emails a time-limited recovery link, which must be completed in the same browser that requested it.

Completing recovery creates a new access key, invalidates the old one and signs the browser in. If the automated flow does not work, contact us.

When you purchase a new scan pack, active unused credits are combined with the new credits and the expiry date extends to 30 days from the new purchase date.

Example: If you have 20 active credits and purchase an Agency pack with 50 credits, you will have 70 credits, all expiring 30 days from the new purchase.

Important: If your credits have already expired when you purchase a new pack, the expired credits are removed. Only active, non-expired credits are extended when you top up.

The Agency Scan Pack is designed for agencies, consultants, and teams managing multiple client websites. It includes:

  • 50 total scans
  • Batch URL scanning - scan multiple websites simultaneously
  • Higher rate limits: 100 scans per hour or 500 scans per day
  • Up to 500 pages per scan, print reports, Excel exports and 90-day scan history, plus all Starter features

Perfect for auditing client portfolios or scanning multiple websites efficiently.

Batch scanning (Agency Pack only) lets you scan multiple websites at once:

  1. Activate your Agency Pack access key
  2. Enable "Batch Mode" on the homepage
  3. Enter multiple URLs (one per line or comma-separated)
  4. Optionally specify pages per URL: example.com (100)
  5. Submit - all scans are queued simultaneously

Each URL counts as one scan from your credit balance. You can scan up to your available credits at once.

There is no separate 100-site batch limit. Batch mode queues URLs up to the number of active credits available. Purchase another Agency pack to add credits, or contact us about Enterprise when you need ongoing monitoring, team access or very large portfolio coverage.

If Agency benefits have expired, purchasing a new Agency pack restores them.

Print-friendly reports provide a clean, professional PDF-style layout optimized for printing or saving. They include all font information, metadata, and licensing indicators in an easy-to-read format without web navigation elements.

📄 View Example Report (PDF)

The scan history dashboard shows all your previous scans in an organized table with details like scan date, website URL, number of pages scanned, and font scan results.

FontReport Dashboard

Privacy and Data

Your privacy is protected:

  • Scan results are not shared with unrelated third parties. Data is only shared with service providers (such as Stripe and Mailgun) as necessary to operate the service
  • Our team may access scan results for debugging, quality assurance, and to improve font detection accuracy. See our Privacy Policy for full details
  • The font analysis data doesn't show licensing status – it's information obtainable from publicly accessible website files anyway
  • Free scan results are retained for up to 7 days
  • Starter results are retained for 30 days, Agency for 90 days and Enterprise for 365 days, unless a specific Enterprise agreement says otherwise
  • You can request account deletion at any time via our contact page

Free scans: Results are stored for up to 7 days for reference, then automatically deleted.

Starter: Results are stored for up to 30 days.

Agency: Results are stored for up to 90 days.

Enterprise: Results, including FontMonitor history, are normally stored for up to 365 days. A customer agreement or an individually adjusted report may specify a different period.

Free, Starter and Agency report links are unlisted but should be treated as shareable URLs. Anyone who receives the link may be able to open it while the report remains available.

Enterprise reports are private and protected by account access and email 2FA by default. An authorised Enterprise owner can explicitly enable a shareable public link for a report and turn sharing off again later.

Enterprise Governance and Access

The Font Inventory gives your team one place to record which fonts have been reviewed. You can mark a font as Compliant or Ignored, add notes about the licence and record a renewal date.

A decision can apply to one website, Google Drive folder or app package, or across the whole account. Renewal reminders help your team review licences before they expire, and the saved status can be included in Enterprise exports.

An Enterprise account can invite up to 10 team members in any mix of co-owners and members.

  • Owner: Controls the account, monitoring, team, font records and sharing settings.
  • Co-owner: Has broad owner-equivalent management access, while the original owner remains the primary account owner.
  • Member: Can access the Enterprise account and run permitted simple scans without receiving all management controls.

Invitations and access are associated with each person's email address, so users should not share one access key across a team.

Enterprise reports are private by default. Account access uses the Enterprise access key together with email 2FA, and a verified browser can be trusted for a limited period.

An authorised owner can enable a public share link for an individual report when an external recipient needs access, then disable that link later. Internal report notes and account-management information are not intended to be exposed through public sharing.

Enterprise plans can include different allowances for:

  • One-off website and PDF scans.
  • Websites monitored by FontMonitor.
  • Google Drive Watched Folders.
  • App-package scans.

These are shown separately in the dashboard so you can see exactly what is included in your plan and what is currently in use.

Advanced Usage

This is a common but risky assumption. Many website owners believe that fonts included with purchased themes or plugins are properly licensed, but this isn't always the case. Plugin and theme developers sometimes:

  • Include fonts without proper redistribution rights
  • Use trial or demo versions that aren't licensed for commercial use
  • Assume end users will obtain their own licenses
  • Bundle fonts that require separate licensing for web use

Even if you paid for the theme or plugin, this doesn't automatically grant you font licensing rights. The theme license typically covers the code and design, not necessarily the fonts. It's worth checking with the theme/plugin developer about font licensing and consider replacing questionable fonts with verified alternatives like Google Fonts.

You can cross-check results by:

  • Using browser developer tools to inspect font usage on individual pages
  • Manually checking CSS files for @font-face declarations
  • Verifying font file URLs by visiting them directly
  • Comparing with your website's font purchase records or CDN logs
  • Source Inspector: Opens the relevant HTML, CSS or JavaScript context and highlights where the font was referenced. Very large or inaccessible source files may be truncated or unavailable.
  • Per-weight breakdown: Shows which files and page references were found for each font weight and style.
  • Discovery and error analytics: Explain how pages, sitemaps and assets were found and where coverage failed.
  • Duplicate Source Files: Uses content hashes to identify identical CSS or JavaScript served from different URLs.
  • Excel export: Agency and Enterprise users can export report evidence for review and record-keeping.

These tools help verify the technical evidence. They do not replace the original licence agreement or legal advice.

  1. Review your font licenses and purchase records
  2. Contact your web development team to verify font sources
  3. For commercial fonts, ensure you have appropriate licenses for web usage
  4. Consider replacing questionable fonts with alternatives from Google Fonts or other free sources
  5. Consult with legal counsel for complex licensing questions

Ready to analyse your fonts?

Get detailed insights into your website's font usage and identify fonts that may need licensing verification in just minutes.

Last updated 7 August 2026