
AnchorKit – Table of Contents Security & Risk Analysis
wordpress.org/plugins/anchorkit-table-of-contentsAccessible table of contents plugin with live preview, Gutenberg blocks, Elementor widgets, and extensive customization.
Is AnchorKit – Table of Contents Safe to Use in 2026?
Generally Safe
Score 100/100AnchorKit – Table of Contents has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "anchorkit-table-of-contents" plugin version 1.0.0 exhibits a strong security posture based on the provided static analysis and vulnerability history. The code demonstrates excellent adherence to secure coding practices, with 100% of SQL queries utilizing prepared statements, and an impressive 99% of output correctly escaped. Furthermore, the plugin incorporates robust security checks, including nonce and capability checks for its AJAX handlers and REST API routes, and crucially, all identified entry points are protected with authentication or permission callbacks. The absence of file operations and external HTTP requests further reduces the attack surface. The plugin's history is also clean, with no recorded CVEs, suggesting a well-maintained and secure codebase over time.
While the static analysis reveals no critical or high-severity issues, and the vulnerability history is pristine, the presence of a bundled library (Freemius v1.0) without a specific version check for potential vulnerabilities is a minor concern. Although no current issues are indicated, outdated bundled libraries can become a vector for zero-day exploits if not actively maintained. Overall, the plugin appears to be secure and well-developed, with the only area for potential improvement being vigilance regarding the security status of bundled third-party components.
Key Concerns
- Bundled library Freemius v1.0 without version check
AnchorKit – Table of Contents Security Vulnerabilities
AnchorKit – Table of Contents Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
AnchorKit – Table of Contents Attack Surface
AJAX Handlers 4
REST API Routes 1
Shortcodes 1
WordPress Hooks 43
Maintenance & Trust
AnchorKit – Table of Contents Maintenance & Trust
Maintenance Signals
Community Trust
AnchorKit – Table of Contents Alternatives
SimpleTOC – Table of Contents Block
simpletoc
SEO-friendly Table of Contents Gutenberg block. No JavaScript and no CSS means faster loading.
Table Of Contents Block
table-of-contents-block
Automatically Add Table of Contents Block for your WordPress Posts & Pages
Table of Contents Generator – SmartTOC Lite
smarttoc-lite
Create a clean, accessible Table of Contents — fast, customizable, and compatible with any theme or editor.
Table Of Contents Block
wpwing-table-of-contents-block
Adds a custom Table of Contents block.
Anik Smart Table of Contents
anik-smart-table-of-contents
A lightweight, SEO-friendly Table of Contents plugin that automatically generates TOC from your headings with smooth scroll and collapsible features.
AnchorKit – Table of Contents Developer Profile
1 plugin · 0 total installs
How We Detect AnchorKit – Table of Contents
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/anchorkit-table-of-contents/build/js/frontend.js/wp-content/plugins/anchorkit-table-of-contents/build/css/frontend.cssanchorkit-table-of-contents/build/js/frontend.js?ver=anchorkit-table-of-contents/build/css/frontend.css?ver=HTML / DOM Fingerprints
anchorkit-toc-containeranchorkit-toc-elementoranchorkit-toc-custom-stylinganchorkit-toc-instance-overrideanchorkit-preview-contentdata-anchorkit-instancedata-anchorkit-auto-theme