
Change Titles Case Security & Risk Analysis
wordpress.org/plugins/change-titles-caseThe title transformation (converts) plugin adds administration functions to the management of posts, pages, categories and most custom content (ACF Co …
Is Change Titles Case Safe to Use in 2026?
Generally Safe
Score 100/100Change Titles Case has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'change-titles-case' plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries, implementing nonce checks, and performing capability checks. The absence of dangerous functions, file operations, and external HTTP requests is also reassuring. Furthermore, the plugin has no known vulnerabilities in its history, suggesting a generally stable codebase.
However, significant security concerns are present. The plugin exposes a single REST API route without proper permission callbacks, creating a direct entry point for potential attackers. While the taint analysis didn't reveal critical or high-severity vulnerabilities, it did identify one flow with unsanitized paths, which warrants investigation, especially in conjunction with the unprotected REST API endpoint. The output escaping is also not perfect, with 20% of outputs not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if untrusted data is involved in these outputs.
In conclusion, while the plugin benefits from a clean vulnerability history and adherence to some secure coding practices, the unprotected REST API endpoint and the presence of an unsanitized path flow represent considerable risks. These specific issues should be addressed to improve the plugin's overall security.
Key Concerns
- REST API route without permission callbacks
- Taint flow with unsanitized paths
- Improper output escaping (20% of outputs)
Change Titles Case Security Vulnerabilities
Change Titles Case Code Analysis
Output Escaping
Data Flow Analysis
Change Titles Case Attack Surface
REST API Routes 1
WordPress Hooks 10
Maintenance & Trust
Change Titles Case Maintenance & Trust
Maintenance Signals
Community Trust
Change Titles Case Alternatives
Simple Admin Language Change
simple-admin-language-change
Change your dashboard language quickly and easily from the admin bar as often as you need.
Admin Slug Column
admin-slug-column
Adds a URL path column to all admin post type edit screens. Works with posts, pages, and any custom post type including WooCommerce products.
Featured Galleries
featured-galleries
Do you like giving posts a Featured Image? Try out a Featured Gallery. It's like a Featured Images ... except as many images as you want.
Admin Customizer
admin-customizer
A plugin for customizing your admin panel.
Backend Designer
backend-designer
Create your own design for the Wordpress Backend with live-preview and customize the Login screen with your own logo and awesome color styles.
Change Titles Case Developer Profile
1 plugin · 80 total installs
How We Detect Change Titles Case
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/change-titles-case/admin/css/change-titles-case-admin.csschange-titles-case-admin.css?ver=HTML / DOM Fingerprints
c_t_c_Change_Case_Data