PWS Better Widget Title Security & Risk Analysis

wordpress.org/plugins/pws-better-widget-title

Hide widget titles that are inside the square brackets, "[]". Handles multiple occurrence. Compatible with WordPress version 3.0+.

0 active installs v1.0.4 PHP + WP 3.0+ Updated May 23, 2020
betterhidewidgetwidget-titles
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PWS Better Widget Title Safe to Use in 2026?

Generally Safe

Score 85/100

PWS Better Widget Title has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "pws-better-widget-title" plugin version 1.0.4 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any identified AJAX handlers, REST API routes, shortcodes, cron events, dangerous functions, file operations, or external HTTP requests significantly limits the plugin's attack surface. Furthermore, the code demonstrates excellent security practices with 100% of SQL queries using prepared statements and 100% of outputs being properly escaped. The lack of any recorded vulnerabilities, past or present, reinforces this positive security assessment. This indicates a well-developed and maintained plugin that prioritizes security. While the limited functionality might contribute to this pristine record, it is a strong indication of good development and testing. The only potential area for caution, albeit minor, is the complete absence of nonce and capability checks, which typically safeguard against certain types of attacks. However, given the minimal attack surface and lack of exploitable code signals, this does not represent an immediate or significant risk in this specific context.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

PWS Better Widget Title Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

PWS Better Widget Title Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

PWS Better Widget Title Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionplugins_loadedincludes\class-pws-better-widget-title.php:142
actionadmin_enqueue_scriptsincludes\class-pws-better-widget-title.php:157
actionadmin_enqueue_scriptsincludes\class-pws-better-widget-title.php:158
filterwidget_titleincludes\class-pws-better-widget-title.php:159
actionwp_enqueue_scriptsincludes\class-pws-better-widget-title.php:174
actionwp_enqueue_scriptsincludes\class-pws-better-widget-title.php:175
filterwp_enqueue_scriptsincludes\class-pws-better-widget-title.php:176
Maintenance & Trust

PWS Better Widget Title Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedMay 23, 2020
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

PWS Better Widget Title Developer Profile

davidhe2018

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PWS Better Widget Title

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pws-better-widget-title/css/pws-better-widget-title-admin.css/wp-content/plugins/pws-better-widget-title/js/pws-better-widget-title-admin.js
Script Paths
/wp-content/plugins/pws-better-widget-title/js/pws-better-widget-title-admin.js
Version Parameters
pws-better-widget-title/css/pws-better-widget-title-admin.css?ver=pws-better-widget-title/js/pws-better-widget-title-admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about PWS Better Widget Title