
Hierarchical Documentation Security & Risk Analysis
wordpress.org/plugins/hierarchical-documentationLets admins create searchable, hierarchically-organized documentation. Supports Markdown and syntax highlighting for code. Requires WP MVC.
Is Hierarchical Documentation Safe to Use in 2026?
Generally Safe
Score 85/100Hierarchical Documentation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The hierarchical-documentation plugin version 1.1 presents a mixed security posture. On the positive side, it boasts a clean vulnerability history with no recorded CVEs, suggesting a generally well-maintained codebase. The static analysis also indicates all SQL queries use prepared statements, a strong practice for preventing SQL injection. However, significant concerns arise from the code signals. The presence of a 'system' dangerous function is a red flag, as this function can execute arbitrary commands on the server, posing a critical risk if not properly controlled. Furthermore, the low percentage of properly escaped output (7%) indicates a high likelihood of cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the plugin's output. The taint analysis showing two flows with unsanitized paths reinforces these concerns, indicating potential for data to be processed in an unsafe manner.
Key Concerns
- Dangerous function 'system' found
- Low percentage of properly escaped output (7%)
- Taint analysis shows unsanitized paths
- No nonce checks implemented
- No capability checks implemented
Hierarchical Documentation Security Vulnerabilities
Hierarchical Documentation Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Hierarchical Documentation Attack Surface
WordPress Hooks 5
Maintenance & Trust
Hierarchical Documentation Maintenance & Trust
Maintenance Signals
Community Trust
Hierarchical Documentation Alternatives
Simple Footnotes
simple-footnotes
Create simple, elegant footnotes on your site. Use the [ref] shortcode and the plugin takes care of the rest.
Shortcode Reference
shortcode-reference
This plugin will provide a list and details about available shortcodes in your current installment. All when you need it most - when editing content.
WH Tweaks
wh-tweaks
Common functionality WordPress core should have but maybe shouldn't.
CitePress – Automatic Citation Generator
citepress-automatic-citation-generator
Generate and display a clean citation box for any WordPress post using customizable academic citation styles.
Shortcode Shortcode
shortcode-shortcode
Provides a [shortcode] shortcode to allow you to show shortcode usage examples without the shortcodes being processed
Hierarchical Documentation Developer Profile
5 plugins · 70 total installs
How We Detect Hierarchical Documentation
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hierarchical-documentation/nest_sortable.js/wp-content/plugins/hierarchical-documentation/preview_markdown.js/wp-content/plugins/hierarchical-documentation/edit_documentation.css/wp-content/plugins/hierarchical-documentation/public_documentation_tree.js/wp-content/plugins/hierarchical-documentation/public_documentation.css/wp-content/plugins/hierarchical-documentation/nest_sortable.js/wp-content/plugins/hierarchical-documentation/preview_markdown.js/wp-content/plugins/hierarchical-documentation/public_documentation_tree.jshierarchical-documentation/nest_sortable.js?ver=hierarchical-documentation/preview_markdown.js?ver=hierarchical-documentation/edit_documentation.css?ver=hierarchical-documentation/public_documentation_tree.js?ver=hierarchical-documentation/public_documentation.css?ver=HTML / DOM Fingerprints
documentation-treedata-iddata-parent-iddata-depthdata-leftdata-rightmvc_js_urlcurrent_documentation_versionurl_documentation_version_namedisplayed_documentation_version