
Correct My Headings Security & Risk Analysis
wordpress.org/plugins/correct-my-headingsIf your subheadings appear on archive pages, they need to start from H3 (because H2 tags are used by the post titles on archive pages).
Is Correct My Headings Safe to Use in 2026?
Generally Safe
Score 85/100Correct My Headings has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'correct-my-headings' v1.0 plugin exhibits a generally strong security posture based on the provided static analysis, with no identified attack surface or dangerous functions. The complete absence of SQL queries, file operations, and external HTTP requests further minimizes potential attack vectors. However, a significant concern arises from the fact that 100% of the identified output operations are not properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the site's output and executed in users' browsers. The plugin also lacks nonce and capability checks, which, while not directly actionable due to the zero attack surface, represents a missed opportunity for robust security practices and could become a weakness if functionality is added in the future. The vulnerability history being completely clean is a positive sign, suggesting a commitment to security or a lack of past exploitable flaws. Overall, the plugin's strengths lie in its minimal attack surface and clean history, but the unescaped output is a critical weakness that needs immediate attention to prevent potential XSS attacks.
Key Concerns
- Output not properly escaped
- Missing nonce checks
- Missing capability checks
Correct My Headings Security Vulnerabilities
Correct My Headings Code Analysis
Output Escaping
Correct My Headings Attack Surface
WordPress Hooks 5
Maintenance & Trust
Correct My Headings Maintenance & Trust
Maintenance Signals
Community Trust
Correct My Headings Alternatives
SocialEars
social-analytics-and-content-seo-using-socialears
SocialEars WordPress plugin allows you to quickly optimize your Blog and Page content for Content SEO and to get great suggestions for Blog titles
OneClickContent – Titles
oneclickcontent-titles
OneClickContent - Titles: Generate SEO-Optimized Titles with OpenAI and Google Gemini. Bring your own API keys.
Protos TOC Generator
protos-toc-generator
Auto-generates a floating or inline table of contents with anchor links based on headings in your post. Improves readability and SEO.
Yoast SEO – Advanced SEO with real-time guidance and built-in AI
wordpress-seo
Improve your SEO with real-time feedback, schema, and clear guidance. Upgrade for AI tools, Google Docs integration, and 24/7 support, no hidden fees.
Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO)
auto-image-attributes-from-filename-with-bulk-updater
Automatically add Image Alt Text, Title, Caption and Description from Filename. Bulk update existing images. Great for Image SEO and Accessibility.
Correct My Headings Developer Profile
2 plugins · 20 total installs
How We Detect Correct My Headings
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.