
F70 Simple Table of Contents Security & Risk Analysis
wordpress.org/plugins/f70-simple-table-of-contentsDisplay a table of contents in your posts by automatically generated from the headings. No Javascript code, simple to use.
Is F70 Simple Table of Contents Safe to Use in 2026?
Generally Safe
Score 92/100F70 Simple Table of Contents has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "f70-simple-table-of-contents" plugin v1.2.3 exhibits a generally good security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events as entry points is a significant strength, limiting the plugin's attack surface. The code also demonstrates a commitment to secure coding practices with 100% of SQL queries using prepared statements, the presence of a nonce check, and two capability checks. Furthermore, the lack of any recorded vulnerabilities, CVEs, or taint flow issues historically suggests a well-maintained and secure plugin.
However, there is a notable concern regarding output escaping. With 50% of outputs not properly escaped, this presents a potential risk for cross-site scripting (XSS) vulnerabilities. While there are no direct indicators of immediate exploitation from the static analysis (e.g., no critical taint flows), unescaped output is a common vector for attacks. The limited scope of the static analysis, particularly the zero taint flows analyzed, means that more complex vulnerabilities might have been missed. Despite this, the overall impression is of a plugin with a strong foundation, but with one area requiring attention to achieve robust security.
In conclusion, the plugin is likely safe for most users due to its minimal attack surface and secure handling of database operations and user permissions. The lack of historical vulnerabilities further bolsters confidence. The primary area of concern is the imperfect output escaping, which, although not currently exploited according to the data, should be addressed to prevent potential XSS issues.
Key Concerns
- 50% of outputs not properly escaped
F70 Simple Table of Contents Security Vulnerabilities
F70 Simple Table of Contents Code Analysis
Output Escaping
F70 Simple Table of Contents Attack Surface
WordPress Hooks 7
Maintenance & Trust
F70 Simple Table of Contents Maintenance & Trust
Maintenance Signals
Community Trust
F70 Simple Table of Contents Alternatives
LuckyWP Table of Contents
luckywp-table-of-contents
Creates SEO-friendly table of contents for your posts/pages. Works automatically or manually (via shortcode, Gutenberg block or widget).
Rich Table of Contents
rich-table-of-content
RTOC is a table of contents generation plugin from Japan that allows anyone to easily create a table of contents. Equipped with the functions of the c …
TOP Table Of Contents
top-table-of-contents
Easily creates SEO-friendly table of contents for your blog posts and pages. Offers both Auto and Manual Insert with highly customization options.
CC-TOC
cc-toc
This plugin automatically creates a table of contents based on html headings in content.
Anik Smart Table of Contents
anik-smart-table-of-contents
A lightweight, SEO-friendly Table of Contents plugin that automatically generates TOC from your headings with smooth scroll and collapsible features.
F70 Simple Table of Contents Developer Profile
2 plugins · 180 total installs
How We Detect F70 Simple Table of Contents
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/f70-simple-table-of-contents/css/style.css/wp-content/plugins/f70-simple-table-of-contents/css/admin-style.cssHTML / DOM Fingerprints
table-of-contentsf70toc-headerid="f70stoc"<div id="f70stoc" class="table-of-contents<span class="f70toc-header">