
WP Subtitle Security & Risk Analysis
wordpress.org/plugins/wp-subtitleAdd subtitles (subheadings) to your pages, posts or custom post types.
Is WP Subtitle Safe to Use in 2026?
Mostly Safe
Score 77/100WP Subtitle is generally safe to use. 2 past CVEs were resolved. Keep it updated.
The wp-subtitle plugin v3.4.2 exhibits a generally strong security posture based on static code analysis. The absence of dangerous functions, the complete reliance on prepared statements for SQL queries, and the proper escaping of all output are commendable practices. Furthermore, the presence of nonce and capability checks on entry points suggests a conscious effort to secure the plugin's functionalities. The attack surface is minimal and appears to be protected.
However, the plugin's vulnerability history presents a significant concern. With two known CVEs, one of which remains unpatched, the plugin has demonstrated a recurring susceptibility to Cross-Site Scripting (XSS) vulnerabilities. The fact that the last reported vulnerability was recent further emphasizes the ongoing risk. While the current version's code analysis doesn't reveal immediate exploitable flaws, the past pattern of XSS issues, especially with an unpatched vulnerability, indicates a potential for future exploits if not addressed.
In conclusion, the static code analysis for wp-subtitle v3.4.2 reveals good security implementation for its current code. Nonetheless, the presence of an unpatched medium-severity vulnerability and a history of XSS issues necessitates caution. The plugin's strengths lie in its secure coding practices, but its weakness lies in its past and present vulnerability landscape, particularly the unpatched CVE.
Key Concerns
- Unpatched medium severity CVE
- History of XSS vulnerabilities
WP Subtitle Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP Subtitle <= 3.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Subtitle <= 3.4 - Cross-Site Scripting
WP Subtitle Code Analysis
Output Escaping
WP Subtitle Attack Surface
Shortcodes 1
WordPress Hooks 30
Maintenance & Trust
WP Subtitle Maintenance & Trust
Maintenance Signals
Community Trust
WP Subtitle Alternatives
Correct My Headings
correct-my-headings
If your subheadings appear on archive pages, they need to start from H3 (because H2 tags are used by the post titles on archive pages).
Secondary Title
secondary-title
Secondary Title is a simple, lightweight plugin that allows you to easily add an alternative title to posts, pages, and/or custom post types.
KIA Subtitle
kia-subtitle
The KIA Subtitle plugin allows you to add a subtitle to your posts.
Subtitles
subtitles
Add subtitles into your WordPress posts, pages, custom post types, and themes. No coding required. Simply activate Subtitles and you're ready.
Product Subtitle For WooCommerce
wc-product-subtitle
Product Subtitle For WooCommerce plugin allows you to easily add a subtitle to your Products.
WP Subtitle Developer Profile
2 plugins · 10K total installs
How We Detect WP Subtitle
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-subtitle/plugin/js/wp-subtitle-admin.js/wp-content/plugins/wp-subtitle/plugin/js/wp-subtitle-admin.jswp-subtitle/plugin/js/wp-subtitle-admin.js?ver=HTML / DOM Fingerprints
inline-edit-col-left-wps-subtitledata-wps_subtitle