Limit Characters in Title Security & Risk Analysis

wordpress.org/plugins/limit-characters-in-title

A plugin that allows character number limit in Title

10 active installs v0.1 PHP + WP 4.0.0+ Updated Mar 6, 2015
editorlimitpageposttitle
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Limit Characters in Title Safe to Use in 2026?

Generally Safe

Score 85/100

Limit Characters in Title has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "limit-characters-in-title" v0.1 plugin exhibits a mixed security posture, with some good practices but significant concerns stemming from its attack surface and taint analysis. While the plugin uses prepared statements for its SQL queries and has a clean vulnerability history, the presence of two unprotected AJAX handlers represents a substantial risk. These unprotected entry points, combined with the two identified taint flows with unsanitized paths that are flagged as high severity, suggest a significant potential for attackers to inject malicious data. The use of the `unserialize` function, though only once, is a known dangerous function that could lead to remote code execution if exploited with untrusted input. The low percentage of properly escaped output further exacerbates these risks, as data could be leaked or manipulated without proper sanitization.

Key Concerns

  • AJAX handlers without auth checks
  • Taint flows with unsanitized paths (High severity)
  • Dangerous function: unserialize
  • Low output escaping percentage
Vulnerabilities
None known

Limit Characters in Title Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Limit Characters in Title Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
2 prepared
Unescaped Output
48
13 escaped
Nonce Checks
4
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$datetime = unserialize( $meta_value );metabox\helpers\cmb_Meta_Box_types.php:486

SQL Query Safety

100% prepared2 total queries

Output Escaping

21% escaped61 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
sanitize_field (metabox\init.php:641)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Limit Characters in Title Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_cmb_oembed_handlermetabox\init.php:1047
noprivwp_ajax_cmb_oembed_handlermetabox\init.php:1048
WordPress Hooks 19
filtercmb_meta_boxeslimit-characters-in-title.php:28
filterthe_titlelimit-characters-in-title.php:29
actioninitlimit-characters-in-title.php:30
actionplugins_loadedlimit-characters-in-title.php:59
filterget_post_metadatametabox\helpers\cmb_Meta_Box_ajax.php:112
filterupdate_post_metadatametabox\helpers\cmb_Meta_Box_ajax.php:114
filtercmb_show_onmetabox\init.php:171
actionadmin_enqueue_scriptsmetabox\init.php:175
actionadmin_menumetabox\init.php:178
actionadd_attachmentmetabox\init.php:179
actionedit_attachmentmetabox\init.php:180
actionsave_postmetabox\init.php:181
actionadmin_enqueue_scriptsmetabox\init.php:182
actionadmin_headmetabox\init.php:185
actionshow_user_profilemetabox\init.php:200
actionedit_user_profilemetabox\init.php:201
actionpersonal_options_updatemetabox\init.php:203
actionedit_user_profile_updatemetabox\init.php:204
actionadmin_headmetabox\init.php:207
Maintenance & Trust

Limit Characters in Title Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedMar 6, 2015
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Limit Characters in Title Developer Profile

Isaias Oliveira

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Limit Characters in Title

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/limit-characters-in-title/metabox/cmb-functions.php/wp-content/plugins/limit-characters-in-title/metabox/css/cmb-styles.css/wp-content/plugins/limit-characters-in-title/metabox/js/cmb-scripts.js
Script Paths
/wp-content/plugins/limit-characters-in-title/metabox/js/cmb-scripts.js
Version Parameters
limit-characters-in-title/metabox/css/cmb-styles.css?ver=limit-characters-in-title/metabox/js/cmb-scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
cmb_metabox
HTML Comments
<!-- You should not edit the code below or things might explode! -->
Data Attributes
data-id="limit_characters_in_title"data-context="side"data-priority="high"
FAQ

Frequently Asked Questions about Limit Characters in Title