F13 Table of Contents Security & Risk Analysis

wordpress.org/plugins/f13-toc

Add a Table of Contents with internal anchor links, built automatically from header tags.

0 active installs v1.0.1 PHP 7.0+ WP 5.0+ Updated Oct 19, 2021
table-of-contentstoc
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is F13 Table of Contents Safe to Use in 2026?

Generally Safe

Score 85/100

F13 Table of Contents has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "f13-toc" plugin v1.0.1 exhibits an exceptionally strong security posture based on the provided static analysis. The complete absence of any identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events is a significant strength. Furthermore, the code demonstrates excellent security practices by exclusively using prepared statements for SQL queries and ensuring all outputs are properly escaped. The lack of file operations, external HTTP requests, and the absence of bundled libraries further reduce the potential attack surface. The taint analysis showing zero flows with unsanitized paths reinforces this positive assessment.

The plugin's vulnerability history is also clean, with no recorded CVEs. This, combined with the static analysis results, suggests a well-developed and secure plugin. However, the lack of any explicit security checks like nonce checks or capability checks across the entire plugin is a minor concern. While there are no apparent vulnerabilities to exploit, the absence of these standard WordPress security mechanisms could be a weakness if new, unforeseen entry points were to be introduced in future versions, or if the plugin relied on other components that did not provide sufficient security. Overall, "f13-toc" v1.0.1 appears to be a highly secure plugin, with its primary weakness being the absence of standard security checks which, in this specific version with no entry points, poses a negligible immediate risk.

Vulnerabilities
None known

F13 Table of Contents Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

F13 Table of Contents Release Timeline

v1.0.1Current
Code Analysis
Analyzed Apr 16, 2026

F13 Table of Contents Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

F13 Table of Contents Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filterthe_contentcontrollers/control.php:7
actionwp_enqueue_scriptsf13-toc.php:24
Maintenance & Trust

F13 Table of Contents Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedOct 19, 2021
PHP min version7.0
Downloads903

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

F13 Table of Contents Developer Profile

f13dev

11 plugins · 80 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect F13 Table of Contents

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/f13-toc/css/f13-toc.css
Version Parameters
f13-toc.css?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- no-f13-toc -->
Data Attributes
id="f13-toc-header"
FAQ

Frequently Asked Questions about F13 Table of Contents