
Subtitle 360 Security & Risk Analysis
wordpress.org/plugins/subtitle-360This plugin creates an option to enter sub heading for pages and posts. You can display the sub title in your theme by using the
Is Subtitle 360 Safe to Use in 2026?
Generally Safe
Score 85/100Subtitle 360 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The subtitle-360 plugin v2.0 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The complete absence of exposed AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code demonstrates good practices by using prepared statements for all SQL queries, implementing nonce checks, and including capability checks. The lack of recorded vulnerabilities and CVEs in its history is a positive indicator of past security diligence.
However, a notable area of concern is the output escaping. With 50% of outputs not being properly escaped, there is a potential risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is directly echoed without adequate sanitization. This is the primary weakness identified in the static analysis. While taint analysis shows no critical or high severity flows, the unescaped output is a tangible risk that could be exploited if an attacker can control the input leading to these outputs.
In conclusion, the subtitle-360 plugin v2.0 has a solid foundation with a minimal attack surface and good internal security practices. The main area requiring attention is improving output escaping to mitigate potential XSS risks. The absence of past vulnerabilities is encouraging, but the unescaped output represents a specific, actionable security concern.
Key Concerns
- Unescaped output in 50% of outputs
Subtitle 360 Security Vulnerabilities
Subtitle 360 Code Analysis
Output Escaping
Subtitle 360 Attack Surface
WordPress Hooks 2
Maintenance & Trust
Subtitle 360 Maintenance & Trust
Maintenance Signals
Community Trust
Subtitle 360 Alternatives
Title Remover
title-remover
Gives you the ability to hide the title of any post, page or custom post type item without affecting menus or titles in the admin area.
Hide Page And Post Title
hide-page-and-post-title
Hide title on single pages and posts.
WP Subtitle
wp-subtitle
Add subtitles (subheadings) to your pages, posts or custom post types.
MM Title Manager — Hide Page and Post Title
hide-titles
Control visibility of post and page titles on your WordPress site.
KIA Subtitle
kia-subtitle
The KIA Subtitle plugin allows you to add a subtitle to your posts.
Subtitle 360 Developer Profile
1 plugin · 100 total installs
How We Detect Subtitle 360
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/subtitle-360/HTML / DOM Fingerprints
subtitle_head<h4 class="subtitle_head"></h4>