Custom Archive Titles Security & Risk Analysis

wordpress.org/plugins/custom-archive-titles

A small and simple plugin to adjust the default texts of archive titles in WordPress

2K active installs v1.1 PHP + WP 4.4+ Updated Jun 6, 2021
archivecategorycustomheadingtitle
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Custom Archive Titles Safe to Use in 2026?

Generally Safe

Score 85/100

Custom Archive Titles has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "custom-archive-titles" v1.1 plugin exhibits a generally good security posture based on the provided static analysis. There are no identified entry points exposed to potential attackers, such as AJAX handlers, REST API routes, or shortcodes, which significantly reduces the attack surface. Furthermore, the code adheres to secure coding practices by exclusively using prepared statements for SQL queries and performing no file operations or external HTTP requests. This indicates a thoughtful approach to development, prioritizing the prevention of common vulnerabilities like SQL injection and remote code execution.

However, a notable concern is the moderate rate of output escaping. With only 53% of outputs properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Unescaped output can allow malicious actors to inject scripts into web pages, which could then be executed in the browsers of other users. The absence of any identified taint flows or dangerous functions is positive, but the lack of comprehensive output escaping remains a critical gap. The plugin's history of zero vulnerabilities further reinforces the impression of a secure codebase, but it's crucial to address the identified output escaping issues to maintain this record.

In conclusion, while the plugin demonstrates strengths in minimizing its attack surface and utilizing secure database interactions, the substantial proportion of unescaped output presents a tangible risk. The lack of recorded vulnerabilities is encouraging but should not detract from the immediate need to rectify the XSS potential. Addressing the output escaping is the most pressing security concern for this plugin.

Key Concerns

  • Unescaped output (potential XSS)
Vulnerabilities
None known

Custom Archive Titles Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Custom Archive Titles Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

53% escaped17 total outputs
Attack Surface

Custom Archive Titles Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadedcustom-archive-titles.php:46
filterget_the_archive_titlecustom-archive-titles.php:113
actionadmin_menuincludes\class-tzcat-settings-page.php:26
actionadmin_initincludes\class-tzcat-settings.php:52
Maintenance & Trust

Custom Archive Titles Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedJun 6, 2021
PHP min version
Downloads54K

Community Trust

Rating100/100
Number of ratings4
Active installs2K
Developer Profile

Custom Archive Titles Developer Profile

ThemeZee

18 plugins · 61K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Custom Archive Titles

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
vcard
FAQ

Frequently Asked Questions about Custom Archive Titles