Title Icon Security & Risk Analysis

wordpress.org/plugins/title-icon

Title Icon plugin displays a small icon or smiley in the title.

20 active installs v0.3 PHP + WP 2.0.2+ Updated Jan 25, 2014
iconiconsimagetitle
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Title Icon Safe to Use in 2026?

Generally Safe

Score 85/100

Title Icon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The "title-icon" plugin v0.3 currently exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any identified dangerous functions, direct SQL queries, file operations, or external HTTP requests is a significant positive. Furthermore, the lack of known CVEs and a clean vulnerability history suggest responsible development practices or limited prior exposure to security testing. However, the analysis does highlight a critical area of concern: all output from the plugin is not properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if any user-supplied data is incorporated into the plugin's output without sanitization. While the attack surface appears to be zero and taint analysis yielded no issues, the unescaped output remains a notable risk that should be addressed.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Title Icon Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Title Icon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Title Icon Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filtertitle_icontitle-icon.php:57
filtertitle_icontitle-icon.php:64
filtertitle_icontitle-icon.php:76
filterthe_titletitle-icon.php:88
Maintenance & Trust

Title Icon Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedJan 25, 2014
PHP min version
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Title Icon Developer Profile

flocsy

4 plugins · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Title Icon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
<img src="/smiley/[^_:]+/[^:]+\.(gif|png)" alt ="" />
FAQ

Frequently Asked Questions about Title Icon