Nested Ordered Lists for Block Editor Security & Risk Analysis

wordpress.org/plugins/nested-ordered-lists-for-block-editor

Extends the list block in Block Editor with options for numbered ordered lists such as 1.1, 1.2, 1.3, 2.1 etc.!

100 active installs v2.2.0 PHP 8.1+ WP 6.6+ Updated Mar 14, 2026
listnumbered-listordered-list
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Nested Ordered Lists for Block Editor Safe to Use in 2026?

Generally Safe

Score 100/100

Nested Ordered Lists for Block Editor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 20d ago
Risk Assessment

The "nested-ordered-lists-for-block-editor" v2.2.0 plugin exhibits a strong security posture based on the provided static analysis. The complete absence of any identified dangerous functions, raw SQL queries, file operations, external HTTP requests, or unsanitized taint flows is highly commendable. The fact that all identified SQL queries utilize prepared statements and all output is properly escaped further reinforces its secure coding practices. The plugin also demonstrates good security hygiene by lacking a significant attack surface, with zero AJAX handlers, REST API routes, shortcodes, or cron events, and all of these potential entry points are correctly secured (where applicable, as there are none in this case).

The vulnerability history of this plugin is also exceptionally clean, with no recorded CVEs of any severity. This indicates a consistent track record of security and stability, suggesting that the developers are either proactive in addressing potential issues or the plugin's functionality does not lend itself to common vulnerability types. The presence of only one capability check, while present, is minimal and doesn't represent a significant concern given the overall lack of attack vectors.

In conclusion, the "nested-ordered-lists-for-block-editor" v2.2.0 plugin appears to be a very secure option. Its strengths lie in its minimal attack surface, diligent use of secure coding practices for SQL and output handling, and a clean vulnerability history. There are no specific technical weaknesses identified in the static analysis or vulnerability history that would warrant significant concern. The absence of nonce checks is noted, but given the complete lack of entry points that would typically require them, this is not a practical concern in this specific instance.

Vulnerabilities
None known

Nested Ordered Lists for Block Editor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Nested Ordered Lists for Block Editor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
14 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

100% escaped14 total outputs
Attack Surface

Nested Ordered Lists for Block Editor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_noticesapp\Transients.php:56
actioninitapp\Update.php:52
filterplugin_row_metanested-ordered-lists-for-block-editor.php:115
actionwp_enqueue_scriptsnested-ordered-lists-for-block-editor.php:156
actionenqueue_block_assetsnested-ordered-lists-for-block-editor.php:224
actioninitnested-ordered-lists-for-block-editor.php:275
filternolg_register_iconsetnested-ordered-lists-for-block-editor.php:287
filternolg_register_iconsetnested-ordered-lists-for-block-editor.php:299
filternolg_register_iconsetnested-ordered-lists-for-block-editor.php:311
actionrender_blocknested-ordered-lists-for-block-editor.php:346
Maintenance & Trust

Nested Ordered Lists for Block Editor Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedMar 14, 2026
PHP min version8.1
Downloads5K

Community Trust

Rating74/100
Number of ratings3
Active installs100
Developer Profile

Nested Ordered Lists for Block Editor Developer Profile

threadi

9 plugins · 950 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Nested Ordered Lists for Block Editor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nested-ordered-lists-for-block-editor/css/style.min.css/wp-content/plugins/nested-ordered-lists-for-block-editor/attributes/list.js/wp-content/plugins/nested-ordered-lists-for-block-editor/attributes/listItem.js/wp-content/plugins/nested-ordered-lists-for-block-editor/admin/style.css/wp-content/plugins/nested-ordered-lists-for-block-editor/css/iconpicker.min.css
Script Paths
/wp-content/plugins/nested-ordered-lists-for-block-editor/attributes/list.js/wp-content/plugins/nested-ordered-lists-for-block-editor/attributes/listItem.js
Version Parameters
nested-ordered-lists-for-block-editor/css/style.min.css?ver=nested-ordered-lists-for-block-editor/attributes/list.js?ver=nested-ordered-lists-for-block-editor/attributes/listItem.js?ver=nested-ordered-lists-for-block-editor/admin/style.css?ver=nested-ordered-lists-for-block-editor/css/iconpicker.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
nolg-list-item-editor-wrapper
JS Globals
window.nolg_config
REST Endpoints
/wp-json/nested-ordered-lists/v1/iconsets
FAQ

Frequently Asked Questions about Nested Ordered Lists for Block Editor