
TM Replace Howdy Security & Risk Analysis
wordpress.org/plugins/tm-replace-howdyBanish the "Howdy" greeting from the WordPress admin area with this simple to use plugin!
Is TM Replace Howdy Safe to Use in 2026?
Use With Caution
Score 63/100TM Replace Howdy has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "tm-replace-howdy" plugin v1.4.2 exhibits a mixed security posture. On the positive side, the static analysis reveals a very small attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events that could be directly exploited. The code also demonstrates good practices by using prepared statements for all SQL queries. However, a significant concern arises from the output escaping, where 56% of the 18 total outputs are not properly escaped, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities. Additionally, the taint analysis identified one flow with an unsanitized path, though it's not categorized as critical or high severity, it still warrants attention.
The vulnerability history presents a substantial risk. The plugin has a known CVE, and critically, it is currently unpatched. This single medium-severity vulnerability, last recorded in June 2025, suggests a pattern of past security weaknesses and a lack of ongoing maintenance to address them. While the absence of critical or high-severity CVEs is positive, the presence of an unpatched medium vulnerability, combined with the observed output escaping issues and unsanitized taint flow, means this plugin should be approached with caution. The small attack surface is a strength, but the unpatched vulnerability and code quality concerns outweigh this positive aspect, suggesting a medium to high overall risk.
Key Concerns
- Unpatched medium vulnerability
- 56% of outputs not properly escaped
- Flow with unsanitized path
TM Replace Howdy Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
TM Replace Howdy <= 1.4.2 - Cross-Site Request Forgery
TM Replace Howdy Code Analysis
Output Escaping
Data Flow Analysis
TM Replace Howdy Attack Surface
WordPress Hooks 5
Maintenance & Trust
TM Replace Howdy Maintenance & Trust
Maintenance Signals
Community Trust
TM Replace Howdy Alternatives
Remove Howdy
remove-howdy
Remove the "Howdy" text in the top right corner of your dashboard.
MC Good-bye Howdy
mc-good-bye-howdy
Easily remove Howdy, replace with your own words or random list, today's day and date, or daypart greeting.
WP Easy Replace Howdy
replace-howdy
Description: This plugin will Replace "Howdy" in the top right corner with "Welcome" of your WordPress dashboard.
Disable/Remove Howdy
disableremove-howdy
Easly Disable or Remove "Howdy" from the the Upper Right corner of your dashboard.
Remove Howdy
replace-howdy-with-hello
This plugin will Replace the "Howdy" with your custom text in the top right corner of your dashboard.
TM Replace Howdy Developer Profile
2 plugins · 210 total installs
How We Detect TM Replace Howdy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tm-replace-howdy/css/tm-replace-howdy.csstm-replace-howdy/css/tm-replace-howdy.css?ver=