A font audit expires the next time someone ships
Last quarter’s scan is a photograph of last quarter’s CSS.
Then a developer runs npm install. A designer drops a new kit into Figma and the handoff ZIP includes the .woff2. A WordPress plugin “adds beautiful headings.” Google Tag Manager injects an Adobe kit for a two-week campaign. Nobody files a license. Nobody opens DevTools. The site is now serving a commercial family you did not choose — and you are still the party a foundry writes to.
That is why one scan is not a compliance program. The live web keeps changing. Rights-holder crawlers do too. Legal risks do not pause because your last report was green.
This is informational, not legal advice.
How a font file gets on the site without a decision
You do not have to “pick Gotham” to ship Gotham. You have to ship a file.
| How it arrives | What it looks like in the repo | Why nobody notices |
|---|---|---|
| npm / yarn package | node_modules/@fontsource/…, a UI kit, a chart library, an icon pack with a bundled face | It is a dependency of a dependency. CI copies /fonts to the CDN. |
| Theme or plugin | A WordPress/Shopify “premium” asset folder | The theme preview used it. Production inherited it. Theme font risks. |
| Design handoff | Desktop OTFs converted to WOFF2 “so it matches Figma” | The desktop seat was never a web license. Figma handoff. |
| Tag manager / A/B tool | A kit URL in GTM, Optimizely, or a chat widget | Marketing can publish CSS without a deploy. |
| Campaign microsite | A landing repo that shares the parent domain’s CDN | The homepage CSS is clean. /lp/ is not. |
| “Temporary” leftover | Files in /assets/fonts after a redesign | The old @font-face still matches a class on one template. |
The honest sentence is: we did not know it was there. That is not a license. It is the usual fact pattern in a demand letter. Foundries treat serving the file as use. “It came with the package” does not transfer a web grant to your domain.
Why “we already scanned” fails six months later
A clean report means: on that date, those URLs, those files. It does not mean:
- next month’s
package-lock.jsonis still OFL-only - the agency’s March microsite was taken down
- Adobe Fonts is still the active kit, not extracted files on your CDN
- a new subdomain was added under the same brand
The legal process starts when what is live and what you own diverge. Detection and inventory are two different facts — why both matter. If you only crawl when someone remembers, you learn about the new family when the foundry does.
A three-page sample is even worse as a habit: the new font often lands on a page you did not hit. Scan the whole site, then repeat. Why three pages are not enough.
A schedule that matches how sites actually change
Pick a cadence that matches your release rhythm, not a calendar slogan.
| Rhythm | When it fits |
|---|---|
| After every production deploy | Product teams with weekly releases — CI via the developer API is the honest version |
| Weekly | Content-heavy sites, many landing pages, frequent plugin updates |
| Monthly | Slower marketing sites that still add pages and tags |
| Always | Launch, redesign, CMS migration, agency handoff, new subdomain |
FontScanner can run the same full-site crawl daily, weekly, or monthly from the dashboard — scheduled scans — without someone remembering to paste the URL. Each cloud run uses a credit, same as a manual crawl. Pair it with My Font Licenses so a new commercial hit shows Missing instead of disappearing into a PDF.
A homepage sniff between crawls is fine for curiosity. It is not the schedule.
What to do when a new family appears
- Confirm it is live (the report’s page list, not Slack folklore).
- Ask how it arrived — lockfile, theme, GTM, handoff ZIP.
- Match it to a registered license. No match → treat as unlicensed until you remove it or buy a web grant.
- Remove the file and the CSS, or replace with an OFL face if the brand does not need that IP.
- Keep the scan and the invoice together. Memory is not proof.
The expensive path is waiting for a letter, then buying retroactive use. The cheap path is seeing the family the week it shipped.
Conclusion
New development does not ask legal for permission. It copies a folder. A font that arrived inside someone else’s package is still your @font-face on your domain.
Scan the whole site. Then scan it again on a schedule that matches how you ship. That is how you find the file before a foundry does.
