
HM Content TOC Security & Risk Analysis
wordpress.org/plugins/hm-content-tocCreates TOC (table of contents) for specified HTML elements from post/page content; to allow jumping to corresponding header by clicking a link in TOC
Is HM Content TOC Safe to Use in 2026?
Generally Safe
Score 85/100HM Content TOC has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "hm-content-toc" v1.0.1 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and the 100% proper output escaping are excellent indicators of secure coding practices. Furthermore, the lack of file operations and external HTTP requests minimizes potential attack vectors. The plugin's vulnerability history is also clean, with no recorded CVEs, which suggests a commitment to security or a lack of targeted exploitation. However, a key area of concern is the complete absence of nonce and capability checks. While the current attack surface is small and appears to have no unprotected entry points, this lack of checks is a significant weakness. Any future expansion of functionality or the introduction of new entry points could easily become vulnerable if these security measures are not implemented.
Key Concerns
- Missing nonce checks
- Missing capability checks
HM Content TOC Security Vulnerabilities
HM Content TOC Release Timeline
HM Content TOC Code Analysis
Output Escaping
HM Content TOC Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
HM Content TOC Maintenance & Trust
Maintenance Signals
Community Trust
HM Content TOC Alternatives
f(x) TOC
fx-toc
Simple Table Of Contents Plugin. Just add [toc] shortcode in content to display.
Shortcode Table of Contents
shortcode-toc
Display an automated table of contents via shortcode.
StockViz
stockviz
The Wordpress shortcode plugin allows you to pull in the latest stock price from within your post.
Adanos Market Sentiment Widgets
adanos-market-sentiment-widgets
Embed self-hosted stock sentiment widgets and shortcodes for WordPress, powered by Adanos.
Cryptocurrency Shortcodes
cryptocurrency-shortcodes
Retrieves information in realtime about cryptocurrencies through our API and display them using our shortcodes. The data retrieved are made available …
HM Content TOC Developer Profile
1 plugin · 10 total installs
How We Detect HM Content TOC
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hm-content-toc/css/style.css/wp-content/plugins/hm-content-toc/js/script.js/wp-content/plugins/hm-content-toc/js/script.jshm-content-toc/css/style.css?ver=hm-content-toc/js/script.js?ver=HTML / DOM Fingerprints
hm_content_toc_placeholderhm-content-toc-wrapperhm-content-toc-listhm-content-toc-itemhm-content-toc-titlehm-content-toc-anchordata-shortcode-ui-editor<div class="hm_content_toc_placeholder" style="display:none"></div>