
In This Article Security & Risk Analysis
wordpress.org/plugins/in-this-articleFetches all H2 and H3 tags from post content and allows displaying them in a clickable list using a shortcode.
Is In This Article Safe to Use in 2026?
Generally Safe
Score 92/100In This Article has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "in-this-article" plugin v1.1.3 exhibits a strong security posture based on the static analysis and vulnerability history provided. The code demonstrates good practices by using prepared statements for all SQL queries and properly escaping all output. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its security. There are no recorded vulnerabilities or CVEs, and the taint analysis found no critical or high-severity issues, indicating a low likelihood of exploitable code flaws. However, a notable area for improvement is the complete lack of nonce checks and capability checks. While the attack surface is small with only one shortcode and no unprotected entry points detected, these missing checks could potentially become a concern if the plugin's functionality evolves or if new vulnerabilities are discovered in WordPress core that could be leveraged by unauthenticated users accessing the shortcode. Overall, the plugin appears secure for its current functionality, but the absence of authorization checks is a weakness that could be addressed to enhance its resilience.
Key Concerns
- Missing nonce checks
- Missing capability checks
In This Article Security Vulnerabilities
In This Article Release Timeline
In This Article Code Analysis
SQL Query Safety
Output Escaping
In This Article Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
In This Article Maintenance & Trust
Maintenance Signals
Community Trust
In This Article Alternatives
Post Content Shortcodes
post-content-shortcodes
Adds shortcodes to display the content of a post or a list of posts.
Custom ShortCode Creator
custom-shortcode-creator
This Custom Shotcode Creator plugin allows you to quickly define custom shortcodes via admin dashboard without any hassle.
Notice Boxes with Shortcodes
notice-boxes-with-shortcodes
This plugin allows you to make notice boxes (styled content boxes of different colors) to display different messages via shortcodes.
Post Content Shortcode
post-content-shortcode
Embed the content of another post using a simple shortcode. Useful for reusing content across pages or posts.
Wpautop Mask
wpautop-mask
Toggle wpautop with shortcodes.
In This Article Developer Profile
6 plugins · 101K total installs
How We Detect In This Article
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/in-this-article/assets/css/itah-style.css/wp-content/plugins/in-this-article/assets/js/itah-script.js/wp-content/plugins/in-this-article/assets/admin/js/itah-admin-script.js/wp-content/plugins/in-this-article/assets/admin/css/itah-admin-style.css/wp-content/plugins/in-this-article/assets/js/itah-script.js/wp-content/plugins/in-this-article/assets/admin/js/itah-admin-script.jsHTML / DOM Fingerprints
ita_in_this_article_wrapperitah_guideitah_headingitah_descriptionid="itah-shortcode"<div class="ita_in_this_article_wrapper"><h4>In this article</h4><ul>