
Secondary Title Security & Risk Analysis
wordpress.org/plugins/secondary-titleSecondary Title is a simple, lightweight plugin that allows you to easily add an alternative title to posts, pages, and/or custom post types.
Is Secondary Title Safe to Use in 2026?
Generally Safe
Score 92/100Secondary Title has a strong security track record. Known vulnerabilities have been patched promptly.
The "secondary-title" plugin version 2.2.0 exhibits a mixed security posture. While it demonstrates good practices in areas like avoiding dangerous functions, raw SQL queries, and file operations, and has a history of resolved vulnerabilities, there are significant concerns regarding output escaping and the presence of unsanitized taint flows. The low percentage of properly escaped output (21%) is a major red flag, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The two identified unsanitized paths in the taint analysis, even without critical or high severity, suggest potential avenues for malicious input to be processed without adequate cleaning. The plugin's past vulnerability history, including a medium severity XSS, reinforces the concern about output handling. Although no unpatched vulnerabilities currently exist and critical/high severity taint flows are absent, the potential for XSS due to poor output escaping and the identified taint flows necessitate careful consideration.
Key Concerns
- Low output escaping rate
- Taint flows with unsanitized paths
- Past medium severity vulnerability (XSS)
Secondary Title Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Secondary Title <= 2.0.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Secondary Title Code Analysis
Output Escaping
Data Flow Analysis
Secondary Title Attack Surface
Shortcodes 1
WordPress Hooks 21
Maintenance & Trust
Secondary Title Maintenance & Trust
Maintenance Signals
Community Trust
Secondary Title Alternatives
WP Subtitle
wp-subtitle
Add subtitles (subheadings) to your pages, posts or custom post types.
Correct My Headings
correct-my-headings
If your subheadings appear on archive pages, they need to start from H3 (because H2 tags are used by the post titles on archive pages).
Custom Archive Titles
custom-archive-titles
A small and simple plugin to adjust the default texts of archive titles in WordPress
SubHeading
subheading
Adds the ability to easily add and display a sub title/heading on any public post type.
Advanced Heading
advanced-heading
Create Advanced Heading with Title, Subtitle and Separator Controls
Secondary Title Developer Profile
1 plugin · 8K total installs
How We Detect Secondary Title
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/secondary-title/assets/css/secondary-title.css/wp-content/plugins/secondary-title/assets/js/secondary-title.js/wp-content/plugins/secondary-title/assets/js/secondary-title.jssecondary-title/assets/css/secondary-title.css?ver=secondary-title/assets/js/secondary-title.js?ver=HTML / DOM Fingerprints
components-text-control__inputid="secondary-title"name="secondary_post_title"title="Enter secondary title here"secondary_title_settings/wp-json/wp/v2/posts?_fields=id,_links.self,title,meta&meta=_secondary_title/wp-json/wp/v2/pages?_fields=id,_links.self,title,meta&meta=_secondary_title