Not sure why everybody is upset that it's a separate app. Google has been doing this with Android for almost a decade now in order to bring new functionality without needing to update the entire operating system.
Get a prepaid with an eSIM with AT&T/Rogers (or any of their MVNO's) for maximum compatibility; cheapest the better. You need an eSIM compatible phone. You can verify this through the carrier's site from your phone.
As far as I'm aware, only new items are charged import fees. She should have the purchase receipt. Used items are just processed like regular mail; could be wrong on that though.
Fonts are a lot more complicated than they appear. Font formats like TTF are binary executable. Basically that means a malicious font file installed can run commands on your system just by displaying what looks like the letter m. Fonts are also processed through an interpreter engine that renders their physical display on screen. Interpreters are nortoriousy a vector of attack because of their low level system access
That's the rule for astronomy. If it happens once, it always happens; we just haven't seen it yet