Correct My Headings Security & Risk Analysis

wordpress.org/plugins/correct-my-headings

If your subheadings appear on archive pages, they need to start from H3 (because H2 tags are used by the post titles on archive pages).

10 active installs v1.0 PHP + WP 2.7+ Updated Apr 10, 2012
contentheadingsseosubheadingstitle
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Correct My Headings Safe to Use in 2026?

Generally Safe

Score 85/100

Correct My Headings has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The 'correct-my-headings' v1.0 plugin exhibits a generally strong security posture based on the provided static analysis, with no identified attack surface or dangerous functions. The complete absence of SQL queries, file operations, and external HTTP requests further minimizes potential attack vectors. However, a significant concern arises from the fact that 100% of the identified output operations are not properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the site's output and executed in users' browsers. The plugin also lacks nonce and capability checks, which, while not directly actionable due to the zero attack surface, represents a missed opportunity for robust security practices and could become a weakness if functionality is added in the future. The vulnerability history being completely clean is a positive sign, suggesting a commitment to security or a lack of past exploitable flaws. Overall, the plugin's strengths lie in its minimal attack surface and clean history, but the unescaped output is a critical weakness that needs immediate attention to prevent potential XSS attacks.

Key Concerns

  • Output not properly escaped
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Correct My Headings Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Correct My Headings Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

Correct My Headings Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_initcorrect-my-headings.php:47
actionadmin_initcorrect-my-headings.php:67
actionadmin_menucorrect-my-headings.php:68
filterplugin_action_linkscorrect-my-headings.php:69
filterthe_contentcorrect-my-headings.php:231
Maintenance & Trust

Correct My Headings Maintenance & Trust

Maintenance Signals

WordPress version tested3.3.2
Last updatedApr 10, 2012
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Correct My Headings Developer Profile

Stefan Matei

2 plugins · 20 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Correct My Headings

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Correct My Headings