
Shortcode in Title Security & Risk Analysis
wordpress.org/plugins/shortcode-in-titleSimple plugin which allows you to add shortcodes to the Title field
Is Shortcode in Title Safe to Use in 2026?
Generally Safe
Score 85/100Shortcode in Title has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "shortcode-in-title" plugin v1.0 exhibits a very strong security posture based on the provided static analysis. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and complete output escaping are excellent indicators of secure coding practices. The plugin also has no file operations or external HTTP requests, further minimizing its attack surface. Furthermore, the vulnerability history is completely clean, with no recorded CVEs, suggesting a history of robust security or perhaps a very limited attack surface that has not been targeted.
While the lack of critical findings in static analysis and vulnerability history is highly positive, it's important to note the complete absence of any nonces or capability checks. This could be a direct reflection of the plugin's limited functionality and attack surface, which is reported as zero entry points. If the plugin truly offers no user-facing interactions that could be exploited or manipulated, then the absence of these checks might be acceptable. However, in general, even for seemingly innocuous plugins, implementing some form of authentication or authorization for any potential interaction points is a best practice to guard against unforeseen vulnerabilities or future feature additions that might introduce risk.
In conclusion, the "shortcode-in-title" v1.0 plugin appears to be very secure, with no immediate vulnerabilities detected in the static analysis and a clean vulnerability history. The strengths lie in its disciplined use of secure coding practices like prepared statements and output escaping. The only area for potential improvement, which might be a consequence of its design rather than an oversight, is the complete lack of nonce or capability checks. For a plugin with zero reported entry points, this might be acceptable, but it's a point to consider for overall security hardening.
Key Concerns
- No nonce checks detected
- No capability checks detected
Shortcode in Title Security Vulnerabilities
Shortcode in Title Code Analysis
Shortcode in Title Attack Surface
WordPress Hooks 1
Maintenance & Trust
Shortcode in Title Maintenance & Trust
Maintenance Signals
Community Trust
Shortcode in Title Alternatives
Date Published Shortcode
date-published-shortcode
Automatically puts in the date that the post was published, using the shortcode [post_published].
Simple Current Date Time
simple-current-date-time
Simple plugin for current, localized dates & times via shortcodes. Use in content, H1 & SEO titles. Lightweight.
Insert Title
insert-title
This plugin simply Insert post's or page's title in content area. If you are really sick of copying and pasting title in content again and a …
Bigboss Recent Post Widget
bigboss-recent-post-widget
Bigboss Recent Post Widget for Showing Recent Post with thumbnail and title [Auto Exclude current post] in widget/sidebar area of your WordPress site …
Current Year Shortcode (for Post Titles)
current-year-shortcode-for-post-titles
Display the current year in post and page titles. Make sure you check the "Enable Shortcode in titles" option in the plugin settings page to …
Shortcode in Title Developer Profile
3 plugins · 260 total installs
How We Detect Shortcode in Title
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.