Stimulate Correct Headings Security & Risk Analysis

wordpress.org/plugins/stimulate-correct-headings

This plugin stimulates WordPress editors to use correct headings for accessibility and seo.

10 active installs v1.0 PHP + WP 3.6+ Updated Aug 27, 2013
accessibilityeditorheadingsseowysiwyg
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Stimulate Correct Headings Safe to Use in 2026?

Generally Safe

Score 85/100

Stimulate Correct Headings has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The "stimulate-correct-headings" v1.0 plugin exhibits an exceptionally small attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the code analysis reveals no dangerous functions, no raw SQL queries (all are prepared), no file operations, and no external HTTP requests. This indicates a strong adherence to secure coding principles in these areas. The complete absence of known vulnerabilities (CVEs) and past security incidents further bolsters its positive security posture.

However, a significant concern arises from the output escaping analysis. With two total outputs and 0% properly escaped, there is a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data or data that could be manipulated and then displayed by the plugin is not being sanitized, leaving the WordPress site vulnerable to malicious code injection. The lack of nonce and capability checks, while less critical given the zero attack surface, also contributes to a less robust security framework. The absence of taint analysis results is neutral, as it could mean no flows were found or the analysis was limited.

Key Concerns

  • Output not properly escaped
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Stimulate Correct Headings Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Stimulate Correct Headings Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

Stimulate Correct Headings Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
filterinitstimulate-correct-headings.php:41
filtermce_buttonsstimulate-correct-headings.php:94
actionadmin_print_footer_scriptsstimulate-correct-headings.php:111
filtertiny_mce_before_initstimulate-correct-headings.php:119
filterinittrunk\stimulate-correct-headings.php:41
filtermce_buttonstrunk\stimulate-correct-headings.php:94
actionadmin_print_footer_scriptstrunk\stimulate-correct-headings.php:111
filtertiny_mce_before_inittrunk\stimulate-correct-headings.php:119
Maintenance & Trust

Stimulate Correct Headings Maintenance & Trust

Maintenance Signals

WordPress version tested3.6.1
Last updatedAug 27, 2013
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Stimulate Correct Headings Developer Profile

bassjobsen

2 plugins · 310 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Stimulate Correct Headings

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

HTML Comments
koptekst
JS Globals
QTags
FAQ

Frequently Asked Questions about Stimulate Correct Headings