WP Total Branding – Complete branding solution for WordPress Security & Risk Analysis

wordpress.org/plugins/wp-total-branding

Make your WordPress truly yours. Customize, clean up, and remove default WordPress footprints, features, and more.

10 active installs v1.3.2 PHP 7.1+ WP 5.2+ Updated Nov 26, 2025
admin-menubrandingcustom-logocustomizewhile-label
99
A · Safe
CVEs total1
Unpatched0
Last CVEJul 11, 2024
Safety Verdict

Is WP Total Branding – Complete branding solution for WordPress Safe to Use in 2026?

Generally Safe

Score 99/100

WP Total Branding – Complete branding solution for WordPress has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jul 11, 2024Updated 4mo ago
Risk Assessment

The plugin "wp-total-branding" v1.3.2 exhibits a mixed security posture. On the positive side, the static analysis reveals a lack of direct attack surface vectors like AJAX handlers, REST API routes, shortcodes, and cron events that are not protected by authentication. Furthermore, all SQL queries are properly prepared, and there are no identified dangerous functions or file operations. The plugin also includes capability checks, which is a good practice for controlling access to its features.

However, there are significant concerns. A substantial portion of output (75%) is not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially given the plugin's historical vulnerability type. The presence of an external HTTP request without any apparent context for its security implications is also a point of attention. The absence of any nonce checks on potential entry points, although the static analysis reports zero entry points, raises a flag if any hidden or future entry points are introduced.

The vulnerability history shows a recent critical vulnerability (CVE) in the medium severity category and a historical pattern of XSS vulnerabilities. This suggests that the developers may struggle with sanitizing user input effectively, leading to exploitable flaws. While the current version may have patched the specific CVE, the recurring nature of XSS is a strong indicator of ongoing security weaknesses. The overall security is compromised by the unescaped output and the past vulnerability trends, despite some positive coding practices.

Key Concerns

  • High percentage of unescaped output
  • Recent CVE (Medium severity)
  • External HTTP request without clear security context
  • 0 nonce checks on potential entry points
Vulnerabilities
1

WP Total Branding – Complete branding solution for WordPress Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-6625medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Total Branding <= 1.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via title Parameter

Jul 11, 2024 Patched in 1.3 (1d)
Code Analysis
Analyzed Mar 17, 2026

WP Total Branding – Complete branding solution for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
4 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

25% escaped16 total outputs
Attack Surface

WP Total Branding – Complete branding solution for WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 35
actionadmin_menuincludes\class-wptb-admin.php:25
actionredux/loadedincludes\class-wptb-admin.php:27
actionadmin_initincludes\modules\admin-bar.php:9
actionadmin_bar_menuincludes\modules\admin-bar.php:25
actionwp_before_admin_bar_renderincludes\modules\admin-bar.php:26
actionadmin_menuincludes\modules\admin-menu.php:7
actionadmin_noticesincludes\modules\admin-message.php:8
actionnetwork_admin_noticesincludes\modules\admin-message.php:9
actionlogin_enqueue_scriptsincludes\modules\custom-css.php:6
actionadmin_enqueue_scriptsincludes\modules\custom-css.php:7
actionwp_enqueue_scriptsincludes\modules\custom-css.php:8
actionadmin_menuincludes\modules\dashboard.php:15
filteradmin_footer_textincludes\modules\dashboard.php:19
filterwp_mail_fromincludes\modules\email.php:11
filterwp_mail_from_nameincludes\modules\email.php:12
actionwp_footerincludes\modules\global-content.php:7
actionlogin_headincludes\modules\login.php:13
filterlogin_headerurlincludes\modules\login.php:14
filterlogin_headertextincludes\modules\login.php:15
filterrest_endpointsincludes\modules\rest-api.php:15
filterjson_enabledincludes\modules\rest-api.php:17
filterjson_jsonp_enabledincludes\modules\rest-api.php:18
filterrest_enabledincludes\modules\rest-api.php:20
filterrest_jsonp_enabledincludes\modules\rest-api.php:21
filterrest_url_prefixincludes\modules\rest-api.php:28
filterget_the_generator_htmlincludes\modules\site-generator.php:22
filterget_the_generator_xhtmlincludes\modules\site-generator.php:23
filterget_the_generator_atomincludes\modules\site-generator.php:24
filterget_the_generator_rss2includes\modules\site-generator.php:25
filterget_the_generator_rdfincludes\modules\site-generator.php:26
filterget_the_generator_commentincludes\modules\site-generator.php:27
filterget_the_generator_exportincludes\modules\site-generator.php:28
actionplugins_loadedwp-total-branding.php:113
actionadmin_noticeswp-total-branding.php:173
actionnetwork_admin_noticeswp-total-branding.php:174
Maintenance & Trust

WP Total Branding – Complete branding solution for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 26, 2025
PHP min version7.1
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WP Total Branding – Complete branding solution for WordPress Developer Profile

Mustafa Uysal

9 plugins · 20K total installs

94
trust score
Avg Security Score
92/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect WP Total Branding – Complete branding solution for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-total-branding/includes/assets/css/custom-css.css/wp-content/plugins/wp-total-branding/includes/assets/js/custom-js.js
Script Paths
/wp-content/plugins/wp-total-branding/includes/assets/js/custom-js.js

HTML / DOM Fingerprints

CSS Classes
wptb_global_headerwptb_global_footer
JS Globals
wptb_global_headerwptb_global_footer
REST Endpoints
/wp-json/
FAQ

Frequently Asked Questions about WP Total Branding – Complete branding solution for WordPress