
Auto Anchor List Security & Risk Analysis
wordpress.org/plugins/auto-anchor-linksCreates anchor links to heading tags in the content and displays automatically at the top of the content, or allows for custom placement with tags.
Is Auto Anchor List Safe to Use in 2026?
Generally Safe
Score 100/100Auto Anchor List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "auto-anchor-links" plugin v1.0 currently exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any identified attack surface entry points, dangerous functions, raw SQL queries, or external HTTP requests is highly positive. Furthermore, the plugin has no recorded vulnerability history, suggesting a history of secure development or limited exposure. However, a significant concern is the complete lack of output escaping. This means that any data processed or displayed by the plugin, even if it originates from a trusted source, is not being sanitized before being rendered in the browser. This could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is somehow incorporated into the output, despite the current analysis not explicitly showing such flows.
While the current analysis shows no taint flows, this is largely due to the absence of identified entry points and code signals that would typically be analyzed by taint analysis tools. The complete absence of nonce and capability checks, coupled with zero output escaping, means that if any entry points were ever introduced, or if the plugin interacted with user-supplied data in unexpected ways, severe security vulnerabilities like Cross-Site Request Forgery (CSRF) and XSS could be easily exploited. The plugin's strengths lie in its apparent minimalism and lack of complex, potentially vulnerable functionalities. However, the complete lack of output escaping represents a critical oversight that needs immediate attention.
Key Concerns
- No output escaping implemented
- No nonce checks implemented
- No capability checks implemented
Auto Anchor List Security Vulnerabilities
Auto Anchor List Code Analysis
Output Escaping
Auto Anchor List Attack Surface
WordPress Hooks 4
Maintenance & Trust
Auto Anchor List Maintenance & Trust
Maintenance Signals
Community Trust
Auto Anchor List Alternatives
Add Anchor Links
add-anchor-links
Creates anchor links to heading tags in the content of selected posts, just like Github does within the Readme.md files.
Copy Link to Heading – Easily add Anchor links for Headings
copy-link-to-heading
Adds a copy link icon to headings for easy copying anchor links, that helps to bookmarking, sharing, and navigation within the content.
Show Some Love from kiki.co.za
show-some-love-kikicoza
Show some love to the people who make it possible to do what you do.
AnchorKit – Table of Contents
anchorkit-table-of-contents
Accessible table of contents plugin with live preview, Gutenberg blocks, Elementor widgets, and extensive customization.
Anik Smart Table of Contents
anik-smart-table-of-contents
A lightweight, SEO-friendly Table of Contents plugin that automatically generates TOC from your headings with smooth scroll and collapsible features.
Auto Anchor List Developer Profile
1 plugin · 50 total installs
How We Detect Auto Anchor List
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/auto-anchor-list/css/mwm-aal.cssmwm-aal.css?ver=1.0.0HTML / DOM Fingerprints
mwm-aal-containermwm-aal-titlemwm-aal-sidebar-container<!--mwm_aal_display-->mwm_aalLoadermwm_aal<div class="mwm-aal-container"><div class='mwm-aal-title'><ol>