All Posts
font auditscheduled scansnpmdependenciesfont compliancelegal risk

Why Regular Font Scans Matter — Fonts Arrive With the Next Deploy

A clean audit in March does not cover the npm install in June. New packages, plugins, and campaigns ship font files you never chose — and foundries still treat that as your use.

Why Regular Font Scans Matter — Fonts Arrive With the Next Deploy

A font audit expires the next time someone ships

Last quarter’s scan is a photograph of last quarter’s CSS.

Then a developer runs npm install. A designer drops a new kit into Figma and the handoff ZIP includes the .woff2. A WordPress plugin “adds beautiful headings.” Google Tag Manager injects an Adobe kit for a two-week campaign. Nobody files a license. Nobody opens DevTools. The site is now serving a commercial family you did not choose — and you are still the party a foundry writes to.

That is why one scan is not a compliance program. The live web keeps changing. Rights-holder crawlers do too. Legal risks do not pause because your last report was green.

This is informational, not legal advice.

How a font file gets on the site without a decision

You do not have to “pick Gotham” to ship Gotham. You have to ship a file.

How it arrivesWhat it looks like in the repoWhy nobody notices
npm / yarn packagenode_modules/@fontsource/…, a UI kit, a chart library, an icon pack with a bundled faceIt is a dependency of a dependency. CI copies /fonts to the CDN.
Theme or pluginA WordPress/Shopify “premium” asset folderThe theme preview used it. Production inherited it. Theme font risks.
Design handoffDesktop OTFs converted to WOFF2 “so it matches Figma”The desktop seat was never a web license. Figma handoff.
Tag manager / A/B toolA kit URL in GTM, Optimizely, or a chat widgetMarketing can publish CSS without a deploy.
Campaign micrositeA landing repo that shares the parent domain’s CDNThe homepage CSS is clean. /lp/ is not.
“Temporary” leftoverFiles in /assets/fonts after a redesignThe old @font-face still matches a class on one template.

The honest sentence is: we did not know it was there. That is not a license. It is the usual fact pattern in a demand letter. Foundries treat serving the file as use. “It came with the package” does not transfer a web grant to your domain.

Why “we already scanned” fails six months later

A clean report means: on that date, those URLs, those files. It does not mean:

  • next month’s package-lock.json is still OFL-only
  • the agency’s March microsite was taken down
  • Adobe Fonts is still the active kit, not extracted files on your CDN
  • a new subdomain was added under the same brand

The legal process starts when what is live and what you own diverge. Detection and inventory are two different facts — why both matter. If you only crawl when someone remembers, you learn about the new family when the foundry does.

A three-page sample is even worse as a habit: the new font often lands on a page you did not hit. Scan the whole site, then repeat. Why three pages are not enough.

A schedule that matches how sites actually change

Pick a cadence that matches your release rhythm, not a calendar slogan.

RhythmWhen it fits
After every production deployProduct teams with weekly releases — CI via the developer API is the honest version
WeeklyContent-heavy sites, many landing pages, frequent plugin updates
MonthlySlower marketing sites that still add pages and tags
AlwaysLaunch, redesign, CMS migration, agency handoff, new subdomain

FontScanner can run the same full-site crawl daily, weekly, or monthly from the dashboard — scheduled scans — without someone remembering to paste the URL. Each cloud run uses a credit, same as a manual crawl. Pair it with My Font Licenses so a new commercial hit shows Missing instead of disappearing into a PDF.

A homepage sniff between crawls is fine for curiosity. It is not the schedule.

What to do when a new family appears

  1. Confirm it is live (the report’s page list, not Slack folklore).
  2. Ask how it arrived — lockfile, theme, GTM, handoff ZIP.
  3. Match it to a registered license. No match → treat as unlicensed until you remove it or buy a web grant.
  4. Remove the file and the CSS, or replace with an OFL face if the brand does not need that IP.
  5. Keep the scan and the invoice together. Memory is not proof.

The expensive path is waiting for a letter, then buying retroactive use. The cheap path is seeing the family the week it shipped.

Conclusion

New development does not ask legal for permission. It copies a folder. A font that arrived inside someone else’s package is still your @font-face on your domain.

Scan the whole site. Then scan it again on a schedule that matches how you ship. That is how you find the file before a foundry does.

Schedule a recurring full-site scan →