
LH Table of Contents Security & Risk Analysis
wordpress.org/plugins/lh-table-of-contentscreate a wiki like TOC (table of contents) in your posts or pages using shortcode.
Is LH Table of Contents Safe to Use in 2026?
Generally Safe
Score 85/100LH Table of Contents has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the 'lh-table-of-contents' plugin v1.05 appears to have a strong security posture. The code analysis reveals a complete absence of dangerous functions, raw SQL queries, unescaped output, file operations, and external HTTP requests. Furthermore, the plugin demonstrates robust security by implementing nonce and capability checks for all its entry points, which are non-existent in this particular analysis. The lack of any recorded CVEs, either historically or currently unpatched, further strengthens this assessment. This indicates that the plugin developers have followed good security practices throughout its development.
While the static analysis points to a very clean codebase with no apparent vulnerabilities or risky patterns, it's important to note that the 'attack surface' is reported as zero. This could mean that the plugin's functionality is minimal or integrated in a way that doesn't expose direct entry points for analysis, or it might be that the analysis tool did not identify any. However, the reported '0 Unprotected' entry points is a positive sign. The absence of any taint flows, critical or high, further reinforces the idea that sensitive data is handled securely within the plugin.
In conclusion, the 'lh-table-of-contents' plugin v1.05 presents a very low risk. The thorough implementation of secure coding practices and the clean vulnerability history suggest a well-maintained and secure plugin. The only area for potential caution is the reported zero attack surface, which, while seemingly positive, might warrant further investigation depending on the plugin's actual functionality and how it interacts with WordPress. However, based purely on the provided data, the plugin is highly secure.
LH Table of Contents Security Vulnerabilities
LH Table of Contents Code Analysis
LH Table of Contents Attack Surface
WordPress Hooks 2
Maintenance & Trust
LH Table of Contents Maintenance & Trust
Maintenance Signals
Community Trust
LH Table of Contents Alternatives
Simple TOC
bainternet-simple-toc
create a wiki like TOC (table of contents) in your posts or pages using shortcode.
Easy Table of Contents
easy-table-of-contents
Adds a user friendly and fully automatic way to create and display a table of contents generated from the page content.
Table of Contents Plus
table-of-contents-plus
A powerful yet user friendly plugin that automatically creates a table of contents. Can also output a sitemap listing all pages and categories.
LuckyWP Table of Contents
luckywp-table-of-contents
Creates SEO-friendly table of contents for your posts/pages. Works automatically or manually (via shortcode, Gutenberg block or widget).
Rich Table of Contents
rich-table-of-content
RTOC is a table of contents generation plugin from Japan that allows anyone to easily create a table of contents. Equipped with the functions of the c …
LH Table of Contents Developer Profile
77 plugins · 15K total installs
How We Detect LH Table of Contents
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lh-table-of-contents/lh-table-of-contents.phpHTML / DOM Fingerprints
lh_table_of_contentslh_toc-index<!-- lh_toc -->lh_toc-<ol class="lh_table_of_contents">