Subtitle 360 Security & Risk Analysis

wordpress.org/plugins/subtitle-360

This plugin creates an option to enter sub heading for pages and posts. You can display the sub title in your theme by using the

100 active installs v2.0 PHP + WP 3.0+ Updated Jan 27, 2015
page-sub-titlepage-titlesubtitle
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Subtitle 360 Safe to Use in 2026?

Generally Safe

Score 85/100

Subtitle 360 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The subtitle-360 plugin v2.0 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The complete absence of exposed AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code demonstrates good practices by using prepared statements for all SQL queries, implementing nonce checks, and including capability checks. The lack of recorded vulnerabilities and CVEs in its history is a positive indicator of past security diligence.

However, a notable area of concern is the output escaping. With 50% of outputs not being properly escaped, there is a potential risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is directly echoed without adequate sanitization. This is the primary weakness identified in the static analysis. While taint analysis shows no critical or high severity flows, the unescaped output is a tangible risk that could be exploited if an attacker can control the input leading to these outputs.

In conclusion, the subtitle-360 plugin v2.0 has a solid foundation with a minimal attack surface and good internal security practices. The main area requiring attention is improving output escaping to mitigate potential XSS risks. The absence of past vulnerabilities is encouraging, but the unescaped output represents a specific, actionable security concern.

Key Concerns

  • Unescaped output in 50% of outputs
Vulnerabilities
None known

Subtitle 360 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Subtitle 360 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
2 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped4 total outputs
Attack Surface

Subtitle 360 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_menuindex.php:16
actionsave_postindex.php:17
Maintenance & Trust

Subtitle 360 Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedJan 27, 2015
PHP min version
Downloads8K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Subtitle 360 Developer Profile

HasanulBanna

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Subtitle 360

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/subtitle-360/

HTML / DOM Fingerprints

CSS Classes
subtitle_head
Shortcode Output
<h4 class="subtitle_head"></h4>
FAQ

Frequently Asked Questions about Subtitle 360