Subtitle Filter Security & Risk Analysis

wordpress.org/plugins/submenu-filter

Adds tha ability to show only a submenu with wp_nav_menu().

10 active installs v1.2 PHP + WP 3.0.0+ Updated Jan 31, 2012
menunav
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Subtitle Filter Safe to Use in 2026?

Generally Safe

Score 85/100

Subtitle Filter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "submenu-filter" v1.2 plugin exhibits a very strong security posture. The absence of any identified dangerous functions, file operations, external HTTP requests, or SQL queries not using prepared statements is commendable. Furthermore, the perfect record of output escaping and the lack of any taint analysis findings suggest a robust approach to preventing common web vulnerabilities. The plugin also has no recorded history of vulnerabilities, which further reinforces its apparent security.

However, the complete absence of any capability checks or nonce checks across all identified entry points (even though the total count is zero) is a significant concern. While there are no identified entry points currently, this indicates a potential oversight in the plugin's design for future expansion or if new entry points are introduced without proper security measures. The plugin's development practices seem to prioritize basic code hygiene but might lack a comprehensive security mindset for authentication and authorization.

In conclusion, the plugin is currently secure due to its minimal attack surface and clean code. The strengths lie in its careful handling of data and SQL. The primary weakness is the lack of built-in authorization and authentication mechanisms, which, while not exploitable now, leaves room for future risks if the attack surface grows. This suggests the plugin is safe for its current limited scope but requires vigilance if further features are added.

Key Concerns

  • No capability checks found
  • No nonce checks found
Vulnerabilities
None known

Subtitle Filter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Subtitle Filter Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Subtitle Filter Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filterwp_nav_menu_objectssubmenu-filter.php:28
Maintenance & Trust

Subtitle Filter Maintenance & Trust

Maintenance Signals

WordPress version tested3.1.4
Last updatedJan 31, 2012
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Subtitle Filter Developer Profile

Marcus Downing

12 plugins · 440 total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Subtitle Filter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Subtitle Filter