
List of Contents Security & Risk Analysis
wordpress.org/plugins/list-of-contentsAutomatically generate a list of contents/table of contents for your posts, pages, and custom post types. Compatible with page builders and plugins.
Is List of Contents Safe to Use in 2026?
Generally Safe
Score 100/100List of Contents has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "list-of-contents" plugin version 1.1.0.2 exhibits a strong security posture based on the provided static analysis. The plugin has a limited attack surface with 3 AJAX handlers, all of which appear to have appropriate authentication and authorization checks (indicated by 0 unprotected entry points and 2 nonce/capability checks). The absence of dangerous functions, direct SQL queries, file operations, and external HTTP requests is commendable. Furthermore, the high percentage of properly escaped output (98%) significantly mitigates the risk of cross-site scripting (XSS) vulnerabilities. The lack of any recorded historical vulnerabilities further reinforces this positive assessment, suggesting a proactive approach to security by the developers.
While the plugin demonstrates excellent security hygiene, the analysis does highlight a minor point for consideration: the inclusion of the Select2 library. While not a direct vulnerability in this specific analysis, bundled libraries can become a security concern if they are outdated and contain known vulnerabilities that are not addressed by the plugin developer. However, with no critical or high severity taint flows identified, and all SQL queries using prepared statements, the immediate risks are minimal. Overall, this plugin appears to be very secure for its current version, with the primary area of attention being the maintenance of bundled libraries.
Key Concerns
- Bundled library: Select2 (potential for outdatedness)
List of Contents Security Vulnerabilities
List of Contents Code Analysis
Bundled Libraries
Output Escaping
List of Contents Attack Surface
AJAX Handlers 3
WordPress Hooks 11
Maintenance & Trust
List of Contents Maintenance & Trust
Maintenance Signals
Community Trust
List of Contents Alternatives
LuckyWP Table of Contents
luckywp-table-of-contents
Creates SEO-friendly table of contents for your posts/pages. Works automatically or manually (via shortcode, Gutenberg block or widget).
Rich Table of Contents
rich-table-of-content
RTOC is a table of contents generation plugin from Japan that allows anyone to easily create a table of contents. Equipped with the functions of the c …
Joli Table Of Contents
joli-table-of-contents
The Best Table of Contents Plugin for WordPress. User-friendly. Gutenberg Block. Fast & Highly customizable. Auto or manual insert.
Heroic Table of Contents
heroic-table-of-contents
Heroic Table of Contents is the easiest way to add a table of contents to your site.
TOP Table Of Contents
top-table-of-contents
Easily creates SEO-friendly table of contents for your blog posts and pages. Offers both Auto and Manual Insert with highly customization options.
List of Contents Developer Profile
2 plugins · 10 total installs
How We Detect List of Contents
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/list-of-contents/assets/css/locp-admin.css/wp-content/plugins/list-of-contents/assets/css/locp-frontend.css/wp-content/plugins/list-of-contents/assets/js/locp-admin.js/wp-content/plugins/list-of-contents/assets/js/locp-frontend.js/wp-content/plugins/list-of-contents/assets/js/locp-admin.js/wp-content/plugins/list-of-contents/assets/js/locp-frontend.jslist-of-contents/assets/css/locp-admin.css?ver=list-of-contents/assets/css/locp-frontend.css?ver=list-of-contents/assets/js/locp-admin.js?ver=list-of-contents/assets/js/locp-frontend.js?ver=HTML / DOM Fingerprints
locp-switchlocp-sliderlocp-rounddata-locp-designlocp_ajax_object/wp-json/list-of-contents/v1/get-headings[toc][list-of-contents]