Force Post Title Security & Risk Analysis

wordpress.org/plugins/force-post-title

This is simple plugin which forces the users to write POST title in Add New Post page.

100 active installs v1.1 PHP + WP 3.x+ Updated Jan 23, 2015
postpublishrequiretitlewithout
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Force Post Title Safe to Use in 2026?

Generally Safe

Score 85/100

Force Post Title has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The 'force-post-title' v1.1 plugin exhibits a strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events, and the complete lack of dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, or identifiable taint flows significantly limits its attack surface. The plugin adheres to good development practices by ensuring that all discovered SQL queries are properly prepared and all output is correctly escaped. The vulnerability history is also clean, with no recorded CVEs, indicating a history of secure development or minimal exposure. However, the complete absence of nonces and capability checks, while not directly exploitable given the zero attack surface, represents a potential weakness if functionality were to be added in the future without proper security controls. Overall, this plugin appears very secure for its current functionality, but a lack of built-in security mechanisms for potential future expansion could be a minor concern.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Force Post Title Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Force Post Title Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Force Post Title Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_initforce_post_title.php:34
actionedit_form_advancedforce_post_title.php:35
Maintenance & Trust

Force Post Title Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedJan 23, 2015
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings4
Active installs100
Developer Profile

Force Post Title Developer Profile

jsphstls

7 plugins · 540 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Force Post Title

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/force-post-title/force_post_title.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Force Post Title