
WP Subtitle Security & Risk Analysis
wordpress.org/plugins/wp-subtitleAdd subtitles (subheadings) to your pages, posts or custom post types.
Is WP Subtitle Safe to Use in 2026?
Generally Safe
Score 98/100WP Subtitle has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The wp-subtitle plugin v3.4.2 exhibits a generally strong security posture based on static code analysis. The absence of dangerous functions, the complete reliance on prepared statements for SQL queries, and the proper escaping of all output are commendable practices. Furthermore, the presence of nonce and capability checks on entry points suggests a conscious effort to secure the plugin's functionalities. The attack surface is minimal and appears to be protected.
However, the plugin's vulnerability history presents a significant concern. With two known CVEs, one of which remains unpatched, the plugin has demonstrated a recurring susceptibility to Cross-Site Scripting (XSS) vulnerabilities. The fact that the last reported vulnerability was recent further emphasizes the ongoing risk. While the current version's code analysis doesn't reveal immediate exploitable flaws, the past pattern of XSS issues, especially with an unpatched vulnerability, indicates a potential for future exploits if not addressed.
In conclusion, the static code analysis for wp-subtitle v3.4.2 reveals good security implementation for its current code. Nonetheless, the presence of an unpatched medium-severity vulnerability and a history of XSS issues necessitates caution. The plugin's strengths lie in its secure coding practices, but its weakness lies in its past and present vulnerability landscape, particularly the unpatched CVE.
Key Concerns
- Unpatched medium severity CVE
- History of XSS vulnerabilities
WP Subtitle Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP Subtitle <= 3.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Subtitle <= 3.4 - Cross-Site Scripting
WP Subtitle Release Timeline
WP Subtitle Code Analysis
Output Escaping
WP Subtitle Attack Surface
Shortcodes 1
WordPress Hooks 30
Maintenance & Trust
WP Subtitle Maintenance & Trust
Maintenance Signals
Community Trust
WP Subtitle Alternatives
Correct My Headings
correct-my-headings
If your subheadings appear on archive pages, they need to start from H3 (because H2 tags are used by the post titles on archive pages).
Dropndot Post Subtitle
dropndot-post-subtitle
Add subtitles to posts, pages, and custom post types. Supports Gutenberg, Classic Editor, WPGraphQL, REST API, and shortcodes.
Secondary Title
secondary-title
Secondary Title is a simple, lightweight plugin that allows you to easily add an alternative title to posts, pages, and/or custom post types.
KIA Subtitle
kia-subtitle
The KIA Subtitle plugin allows you to add a subtitle to your posts.
Subtitles
subtitles
Add subtitles into your WordPress posts, pages, custom post types, and themes. No coding required. Simply activate Subtitles and you're ready.
WP Subtitle Developer Profile
3 plugins · 10K total installs
How We Detect WP Subtitle
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-subtitle/plugin/js/wp-subtitle-admin.js/wp-content/plugins/wp-subtitle/plugin/js/wp-subtitle-admin.jswp-subtitle/plugin/js/wp-subtitle-admin.js?ver=HTML / DOM Fingerprints
inline-edit-col-left-wps-subtitledata-wps_subtitle