Title Toggle for Storefront Theme Security & Risk Analysis

wordpress.org/plugins/storefront-title-toggle

Hide titles on a per post/page basis. Must be using the Storefront theme.

3K active installs v1.3.0 PHP + WP 4.0.0+ Updated Oct 1, 2024
removestorefronttitletoggle
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Title Toggle for Storefront Theme Safe to Use in 2026?

Generally Safe

Score 92/100

Title Toggle for Storefront Theme has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The storefront-title-toggle plugin v1.3.0 presents a generally good security posture based on the provided static analysis. The plugin exhibits strong adherence to secure coding practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and having no file operations or external HTTP requests. The presence of a nonce check and a capability check further indicates an effort to protect against common attack vectors. Crucially, the complete absence of critical and high severity taint flows is a significant positive indicator.

However, a notable concern arises from the output escaping. With 5 total outputs and 0% properly escaped, this indicates a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data displayed by this plugin that is not properly escaped can be exploited by attackers to inject malicious scripts into the user's browser. The plugin's vulnerability history is clean, with no recorded CVEs, which is reassuring but doesn't negate the present code-level risks. In conclusion, while the plugin demonstrates a solid foundation in secure development by limiting its attack surface and implementing fundamental security checks, the lack of proper output escaping represents a clear and actionable security weakness that needs immediate attention.

Key Concerns

  • 0% of outputs properly escaped (XSS risk)
Vulnerabilities
None known

Title Toggle for Storefront Theme Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Title Toggle for Storefront Theme Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
0 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped5 total outputs
Attack Surface

Title Toggle for Storefront Theme Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actioninitstorefront-title-toggle.php:115
actioninitstorefront-title-toggle.php:117
actionadd_meta_boxesstorefront-title-toggle.php:228
actionsave_poststorefront-title-toggle.php:229
actionadmin_noticesstorefront-title-toggle.php:230
actionwpstorefront-title-toggle.php:231
filterstorefront_customizer_morestorefront-title-toggle.php:234
actionstorefront_pagestorefront-title-toggle.php:372
filterwoocommerce_show_page_titlestorefront-title-toggle.php:384
actionwoocommerce_single_product_summarystorefront-title-toggle.php:389
Maintenance & Trust

Title Toggle for Storefront Theme Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedOct 1, 2024
PHP min version
Downloads102K

Community Trust

Rating90/100
Number of ratings17
Active installs3K
Developer Profile

Title Toggle for Storefront Theme Developer Profile

wooassist

5 plugins · 10K total installs

92
trust score
Avg Security Score
89/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Title Toggle for Storefront Theme

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/storefront-title-toggle/assets/js/admin/settings.js/wp-content/plugins/storefront-title-toggle/assets/css/admin/settings.css
Script Paths
/wp-content/plugins/storefront-title-toggle/assets/js/admin/settings.js
Version Parameters
storefront-title-toggle/assets/js/admin/settings.js?ver=storefront-title-toggle/assets/css/admin/settings.css?ver=

HTML / DOM Fingerprints

CSS Classes
woa-sf-title-toggle
Data Attributes
woa_sf_title_toggle_nonce
FAQ

Frequently Asked Questions about Title Toggle for Storefront Theme