Is Fontconfig Safe?

Use Fontconfig with some caution. Fontconfig is a Homebrew formula with a Nerq Trust Score of 64.5/100 (C+), based on 3 independent data dimensions. It is below the recommended threshold of 70. Security: 90/100. Popularity: 75/100. Data sourced from Homebrew formulae database and GitHub (homebrew-core). Last updated: 2026-03-28. Machine-readable data (JSON).

Is Fontconfig safe?

CAUTION — Fontconfig has a Nerq Trust Score of 64.5/100 (C+). It has moderate trust signals but shows some areas of concern that warrant attention. Suitable for development use — review security and maintenance signals before production deployment.

Trust Score Breakdown

Security
90
Popularity
75

Key Findings

Security score: 90/100 (strong)
Popularity: 75/100 — community adoption

Details

AuthorUnknown
Categoryhomebrew
SourceN/A

Fontconfig Across Platforms

Same developer/company in other registries:

fontconfig
60/100 · crates

Safety Guide: Fontconfig

What is Fontconfig?

Fontconfig is a Homebrew formula — XML-based font configuration API for X Windows.

How to Verify Safety

Homebrew formulas are community-reviewed. Check formulae.brew.sh.

You can also check the trust score via API: GET /v1/preflight?target=fontconfig

Key Safety Concerns for Homebrew formulas

When evaluating any Homebrew formula, watch for: source build integrity, dependency chain.

Trust Assessment

Fontconfig has a Nerq Trust Score of 64/100 (C+) and has not yet reached Nerq trust threshold (70+). This score is based on automated analysis of security, maintenance, community, and quality signals.

Key Takeaways

Detailed Score Analysis

DimensionScore
Security90/100
Privacy80/100
Reliability80/100
Transparency85/100
Maintenance60/100

Based on 5 dimensions. Data from Homebrew formulae database and GitHub (homebrew-core).

What data does Fontconfig collect?

Fontconfig has a privacy score of 80/100. Review the documentation and privacy policy for data handling details.

Full analysis: Fontconfig Privacy Report · Privacy review

Is Fontconfig secure?

Security score: 90/100. This meets the recommended security threshold for production use.

Nerq monitors this entity against NVD, OSV.dev, and registry-specific vulnerability databases for ongoing security assessment.

Full analysis: Fontconfig Security Report

Fontconfig Across Platforms

Same developer/company in other registries:

fontconfig (crates, 60/100)

How we calculated this score

Fontconfig's trust score of 64.5/100 (C+) is computed from Homebrew formulae database and GitHub (homebrew-core). The score reflects 5 independent dimensions: security (90/100), privacy (80/100), reliability (80/100), transparency (85/100), maintenance (60/100). Each dimension is weighted equally to produce the composite trust score.

Nerq analyzes over 7.5 million entities across 26 registries using the same methodology, enabling direct cross-entity comparison. Scores are updated continuously as new data becomes available.

This page was last reviewed on March 28, 2026. Data version: 1.0.

Full methodology documentation · Machine-readable data (JSON API)

Frequently Asked Questions

Is Fontconfig safe to use?
Use with some caution. fontconfig has a Nerq Trust Score of 64.5/100 (C+). Strongest signal: security (90/100). Score based on security (90/100), popularity (75/100).
What is Fontconfig's trust score?
fontconfig: 64.5/100 (C+). Score based on: security (90/100), popularity (75/100). Scores update as new data becomes available. API: GET nerq.ai/v1/preflight?target=fontconfig
What are safer alternatives to Fontconfig?
In the homebrew category, more Homebrew formulas are being analyzed — check back soon. fontconfig scores 64.5/100.
Is Fontconfig actively maintained?
Fontconfig maintenance score: N/A. Check the repository for recent commit activity and issue responsiveness.
How was Fontconfig reviewed?
Nerq analyzes Fontconfig using data from Homebrew formulae database and GitHub (homebrew-core). Trust score: 64.5/100 (C+).
API: /v1/preflight Trust Badge API Docs

Disclaimer: Nerq trust scores are automated assessments based on publicly available signals. They are not endorsements or guarantees. Always conduct your own due diligence.