
FriendlyCase Security & Risk Analysis
wordpress.org/plugins/friendlycaseReformat titles from 'ALL CAPS' to 'All Caps' and enable friendly, word capitalization in posts, pages and more.
Is FriendlyCase Safe to Use in 2026?
Generally Safe
Score 85/100FriendlyCase has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "friendlycase" plugin version 1.0.7 exhibits a strong security posture based on the provided static analysis and vulnerability history. The complete absence of identified attack surface points, dangerous functions, raw SQL queries, file operations, external HTTP requests, and taint flows suggests a well-secured codebase. The presence of 100% prepared statements for SQL queries is a significant positive indicator of safe database interaction.
However, the static analysis reveals a critical weakness: 0% of output escaping is properly implemented. This means that any dynamic data displayed by the plugin, even if not directly exploitable through the analyzed entry points, could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is reflected directly in the output. The lack of capability checks and nonce checks, while not directly linked to discovered entry points, are generally considered good security practices for WordPress plugins, and their absence leaves room for potential privilege escalation or unauthorized actions if new, unprotected entry points were to be introduced in future versions.
Overall, the plugin's strength lies in its minimal and seemingly secure attack surface and database handling. The primary and significant concern is the complete lack of output escaping, which is a fundamental security requirement. The absence of any historical vulnerabilities is encouraging but should not negate the importance of addressing the identified output escaping issue.
Key Concerns
- Output escaping is not implemented
FriendlyCase Security Vulnerabilities
FriendlyCase Code Analysis
Output Escaping
FriendlyCase Attack Surface
WordPress Hooks 3
Maintenance & Trust
FriendlyCase Maintenance & Trust
Maintenance Signals
Community Trust
FriendlyCase Alternatives
WP Title Case
wp-title-case
Automatically applied title case rules to WordPress titles. This plugin automatically updates Page and Post titles to follow title casing rules.
Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO)
auto-image-attributes-from-filename-with-bulk-updater
Automatically add Image Alt Text, Title, Caption and Description from Filename. Bulk update existing images. Great for Image SEO and Accessibility.
Title Remover
title-remover
Gives you the ability to hide the title of any post, page or custom post type item without affecting menus or titles in the admin area.
Auto Featured Image (Auto Post Thumbnail)
auto-post-thumbnail
Automatically generate, assign, and manage featured images in bulk so every post on your site has a featured image.
Phoenix Media Rename
phoenix-media-rename
The Phoenix Media Rename plugin allows you to easily rename (and retitle) your media files, once uploaded.
FriendlyCase Developer Profile
1 plugin · 10 total installs
How We Detect FriendlyCase
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
fc_lcfc_ucfc_igLicense: GPLCopyright (C) 2011 - 2012, Joseph Kelter, Saul Rosenbaum,Sharon Rooney Rosshttp://badcat.com , http://visualchutzpah.com,+15 morefc-wrapfc-tablefc-rowfc-textarea