Hierarchy Pages Nav Security & Risk Analysis

wordpress.org/plugins/hierarchy-pages-nav

Document hierarchy pages like a book and provide easy navigation between pages.

0 active installs v0.9.7 PHP 7.4+ WP 6.2+ Updated Unknown
documenthierarchynavigationparent-pagetable-of-contents
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Hierarchy Pages Nav Safe to Use in 2026?

Generally Safe

Score 100/100

Hierarchy Pages Nav has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "hierarchy-pages-nav" plugin v0.9.7 demonstrates a generally strong security posture, with no known vulnerabilities or CVEs in its history. The static analysis reveals excellent practices in crucial areas like SQL query preparation and output escaping, with 100% of both categories being handled securely. Furthermore, all identified entry points, including AJAX handlers, appear to have proper authentication and capability checks, and there are no file operations or external HTTP requests, which significantly reduces potential attack vectors.

However, a notable concern arises from the taint analysis, which identified 5 flows with unsanitized paths, all categorized as high severity. While these do not directly translate to immediate vulnerabilities given the lack of known CVEs and apparent authentication checks on entry points, they represent potential weak points that could be exploited if the application logic or authentication mechanisms are ever compromised or bypassed. The presence of nonce checks and capability checks on most entry points is positive, but the 5 unsanitized taint flows indicate that data is flowing in a way that could be manipulated if an attacker gains a foothold.

In conclusion, the plugin benefits from a clean vulnerability history and sound coding practices in many areas. The primary weakness lies in the identified taint flows, which, despite the current lack of exploitable vulnerabilities, warrants attention to ensure the sanitization of these paths is robust. This plugin is generally secure, but the taint analysis suggests room for improvement in data handling to further harden its security.

Key Concerns

  • High severity unsanitized taint flows found
Vulnerabilities
None known

Hierarchy Pages Nav Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Hierarchy Pages Nav Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
42 prepared
Unescaped Output
0
129 escaped
Nonce Checks
5
Capability Checks
6
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared42 total queries

Output Escaping

100% escaped129 total outputs
Data Flows
5 unsanitized

Data Flow Analysis

5 flows5 with unsanitized paths
ajax_hpgnav_search (hpgnav-search.php:160)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Hierarchy Pages Nav Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 6

noprivwp_ajax_hpgnav_searchhpgnav-search.php:15
authwp_ajax_hpgnav_searchhpgnav-search.php:16
authwp_ajax_hpgnav_list_refreshhpgnav-setting.php:42
authwp_ajax_hpgnav_bulk_actionhpgnav-setting.php:43
authwp_ajax_hpgnav_get_tochpgnav-toc.php:113
noprivwp_ajax_hpgnav_get_tochpgnav-toc.php:114
WordPress Hooks 14
actionplugins_loadedhierarchy-pages-nav.php:102
filterhpgnav_additional_nav_iconhpgnav-search.php:13
actiontransition_post_statushpgnav-setting.php:16
actiondeleted_posthpgnav-setting.php:17
actionupdate_option_permalink_structurehpgnav-setting.php:18
actionadmin_menuhpgnav-setting.php:21
actionadmin_inithpgnav-setting.php:27
filterpost_password_expireshpgnav-toc.php:20
actiontemplate_redirecthpgnav-toc.php:30
actionwp_headhpgnav-toc.php:58
filterpost_password_requiredhpgnav-toc.php:71
filterthe_contenthpgnav-toc.php:108
actionwp_footerhpgnav-toc.php:187
actioninithpgnav-toc.php:430
Maintenance & Trust

Hierarchy Pages Nav Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedUnknown
PHP min version7.4
Downloads506

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Hierarchy Pages Nav Developer Profile

enomoto celtislab

12 plugins · 9K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Hierarchy Pages Nav

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Hierarchy Pages Nav