
Format Media Titles Security & Risk Analysis
wordpress.org/plugins/format-media-titlesAutomatically formats the title (and optionally the ALT field) for new media uploads. No need to manually edit the title anymore every time you upload …
Is Format Media Titles Safe to Use in 2026?
Generally Safe
Score 85/100Format Media Titles has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "format-media-titles" plugin v1.0.0 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any recorded CVEs, including currently unpatched vulnerabilities, is a significant positive indicator. Furthermore, the plugin demonstrates good practices by not utilizing dangerous functions, performing file operations, or making external HTTP requests. The fact that all SQL queries are prepared statements is also a strong point against common SQL injection vulnerabilities.
However, a critical concern arises from the complete lack of output escaping. With 4 total outputs analyzed and 0% properly escaped, this presents a significant risk for Cross-Site Scripting (XSS) vulnerabilities. Any data that is displayed to users, especially if it originates from user input or external sources, could potentially be exploited. Additionally, the plugin lacks nonce and capability checks, which, while not directly flagged as issues given the zero attack surface, could become a vector if the plugin's functionality were to expand or change in the future, allowing for potential unauthorized actions or CSRF attacks.
In conclusion, while the plugin is free from known historical vulnerabilities and employs secure database practices, the unescaped output is a glaring security weakness that requires immediate attention. The lack of authentication checks, while not an immediate problem with the current attack surface, represents a potential future risk. Addressing the output escaping is paramount to mitigating XSS threats.
Key Concerns
- Unescaped output
- Missing nonce checks
- Missing capability checks
Format Media Titles Security Vulnerabilities
Format Media Titles Code Analysis
Output Escaping
Format Media Titles Attack Surface
WordPress Hooks 5
Maintenance & Trust
Format Media Titles Maintenance & Trust
Maintenance Signals
Community Trust
Format Media Titles Alternatives
Bootstrap img-responsive
img-responsive
Automatically add img-responsive class to all post and page content.
Bootstrap v4 img-fluid
img-fluid
Automatically add img-fluid class to all post and page content.
Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO)
auto-image-attributes-from-filename-with-bulk-updater
Automatically add Image Alt Text, Title, Caption and Description from Filename. Bulk update existing images. Great for Image SEO and Accessibility.
Bulk Auto Image Alt Text (Alt tag, Alt attribute) optimizer (image SEO)
bulk-image-alt-text-with-yoast
Auto optimize all image alt text (+ Woocommerce ), per page & product, from Yoast SEO / Rank Math optimization settings (keywords).
Media Library Helper — Bulk edit image ALT, caption & description
media-library-helper
Add or edit or bulk edit image ALT tag, caption & description with one click straight from the WordPress media library to improve your SEO score.
Format Media Titles Developer Profile
11 plugins · 109K total installs
How We Detect Format Media Titles
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/format-media-titles/images/wpgo_plugins_logo.png/wp-content/plugins/format-media-titles/images/twitter.png/wp-content/plugins/format-media-titles/images/facebook.png/wp-content/plugins/format-media-titles/images/yt.pngHTML / DOM Fingerprints
pcdmfmt_options