
MK Table of Contents Security & Risk Analysis
wordpress.org/plugins/mk-table-of-contentsThis Plugin adds a TOC to a post via the shortcode [toc].
Is MK Table of Contents Safe to Use in 2026?
Generally Safe
Score 85/100MK Table of Contents has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mk-table-of-contents plugin version 2.2 exhibits a generally good security posture based on the provided static analysis. The absence of known CVEs and the plugin's history of no recorded vulnerabilities are positive indicators. The code analysis shows a minimal attack surface with only one shortcode entry point, and notably, all SQL queries are properly prepared. File operations and external HTTP requests are also absent, reducing potential attack vectors. However, there are some areas for improvement. The lack of nonce checks on the shortcode, combined with only one capability check and a significant portion of output not being properly escaped (25%), presents potential risks. While taint analysis shows no critical or high severity issues, the unescaped output could be exploited in combination with other factors to lead to Cross-Site Scripting (XSS) vulnerabilities.
Key Concerns
- Unescaped output found (25%)
- No nonce checks on shortcode
- Limited capability checks on entry point
MK Table of Contents Security Vulnerabilities
MK Table of Contents Release Timeline
MK Table of Contents Code Analysis
Bundled Libraries
Output Escaping
MK Table of Contents Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
MK Table of Contents Maintenance & Trust
Maintenance Signals
Community Trust
MK Table of Contents Alternatives
Seo Friendly Table of Contents
seo-friendly-table-of-contents
A simple seo friendly table of contents plugin that does not require editing in your themes source code.
Promasterweb – Sommaire automatique
promasterweb-sommaire-automatique
Automatically generates a clean, SEO-friendly table of contents from H2 headings in your WordPress posts — zero configuration required.
Easy Table of Contents
easy-table-of-contents
Adds a user friendly and fully automatic way to create and display a table of contents generated from the page content.
Table of Contents Plus
table-of-contents-plus
A powerful yet user friendly plugin that automatically creates a table of contents. Can also output a sitemap listing all pages and categories.
LuckyWP Table of Contents
luckywp-table-of-contents
Creates SEO-friendly table of contents for your posts/pages. Works automatically or manually (via shortcode, Gutenberg block or widget).
MK Table of Contents Developer Profile
2 plugins · 0 total installs
How We Detect MK Table of Contents
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mk-table-of-contents/css/mk-toc.css/wp-content/plugins/mk-table-of-contents/js/mk-toc.js/wp-content/plugins/mk-table-of-contents/css/mk-toc-mce.css/wp-content/plugins/mk-table-of-contents/js/mk-toc-tinymce-button.js/wp-content/plugins/mk-table-of-contents/js/mk-toc.jsmk-table-of-contents/css/mk-toc.css?ver=mk-table-of-contents/js/mk-toc.js?ver=mk-table-of-contents/css/mk-toc-mce.css?ver=mk-table-of-contents/js/mk-toc-tinymce-button.js?ver=HTML / DOM Fingerprints
mk-tocmk-toc-navmk-toc-headingmk-toc-listmk-toc-anchor-linkmk_toc_sc_button_keymk_toc_jsvar<nav class="mk-toc mk-toc-nav"><p class="mk-toc mk-toc-heading"><ul class="mk-toc mk-toc-list"><a href="#