
SubHeading Security & Risk Analysis
wordpress.org/plugins/subheadingAdds the ability to easily add and display a sub title/heading on any public post type.
Is SubHeading Safe to Use in 2026?
Generally Safe
Score 85/100SubHeading has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "subheading" plugin v1.8.1 exhibits a generally strong security posture based on the static analysis and vulnerability history provided. The complete absence of detected dangerous functions, raw SQL queries, file operations, and external HTTP requests is highly commendable. Furthermore, the high percentage of properly escaped output (91%) and the presence of nonce and capability checks indicate good development practices for protecting against common web vulnerabilities. The lack of any recorded CVEs, past or present, further reinforces this positive assessment, suggesting a mature and well-maintained codebase.
However, the analysis of entry points is a significant concern. The total absence of AJAX handlers, REST API routes, shortcodes, and cron events, while seemingly good, can also indicate a limited plugin functionality or, more critically, that the plugin might not be performing any essential tasks or interacting with the WordPress core in ways that would necessitate these common entry points. The absence of taint analysis flows is also notable; while this could mean the code is secure, it might also suggest that the analysis environment or tooling did not find sufficient complex data flows to analyze, which could mask potential issues if the plugin were to evolve with more complex user input handling.
In conclusion, "subheading" v1.8.1 appears to be a secure plugin with strong internal coding practices. Its vulnerability history is clean, and the static analysis reveals minimal risk. The primary area of potential concern lies in the extremely limited attack surface and the lack of observable taint flows, which warrants further investigation into the plugin's actual functionality and how it handles any potential user-supplied data, however minimal.
SubHeading Security Vulnerabilities
SubHeading Code Analysis
Output Escaping
SubHeading Attack Surface
WordPress Hooks 11
Maintenance & Trust
SubHeading Maintenance & Trust
Maintenance Signals
Community Trust
SubHeading Alternatives
WP Subtitle
wp-subtitle
Add subtitles (subheadings) to your pages, posts or custom post types.
Secondary Title
secondary-title
Secondary Title is a simple, lightweight plugin that allows you to easily add an alternative title to posts, pages, and/or custom post types.
Small Heading For Post Title
small-heading-for-post-title
The Small Heading For Post Title is a simple plugin for displaying small headings (subtitles) before or after post title.
Admin Menu Blank Template Plugin
admin-menu-tamplate-plugin
Admin Menu Template Plugin make plugin development easy like drag and drop.
Correct My Headings
correct-my-headings
If your subheadings appear on archive pages, they need to start from H3 (because H2 tags are used by the post titles on archive pages).
SubHeading Developer Profile
4 plugins · 3K total installs
How We Detect SubHeading
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/subheading/admin.js/wp-content/plugins/subheading/admin.jsHTML / DOM Fingerprints
SubHeading