NexIndex – Auto Table of Contents & SEO Links Security & Risk Analysis

wordpress.org/plugins/nexindex

NexIndex is the Next-Gen Table of Contents plugin. Beautiful skins, Smart SEO Anchors, Inline Headings (News Style), and Mobile-First design.

0 active installs v1.2.0 PHP 7.4+ WP 5.8+ Updated Dec 8, 2025
indexnavigationseotable-of-contentstoc
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is NexIndex – Auto Table of Contents & SEO Links Safe to Use in 2026?

Generally Safe

Score 100/100

NexIndex – Auto Table of Contents & SEO Links has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The nexindex v1.2.0 plugin demonstrates a strong security posture based on the provided static analysis. The absence of any identified attack surface through AJAX, REST API, shortcodes, or cron events, and the lack of dangerous functions, SQL queries not using prepared statements, and file operations are all positive indicators. Furthermore, the plugin exhibits excellent output escaping practices and a negligible number of external HTTP requests, suggesting a robust approach to preventing common web vulnerabilities.

While the code analysis reveals no critical or high-severity taint flows and the plugin has no recorded vulnerability history, there are minor areas for improvement. The lack of nonce checks is a potential concern, especially if future updates introduce or expose any entry points. Similarly, the reliance on capability checks for only two instances might suggest that other areas, if they exist, might not be adequately secured. The bundling of TinyMCE, while a common library, could be a concern if it's an outdated version, as it might carry its own set of vulnerabilities.

Overall, nexindex v1.2.0 appears to be a secure plugin with good development practices in place. The limited attack surface and thorough code sanitization are significant strengths. However, the absence of nonce checks and the potential for an outdated bundled library warrant careful consideration for any further development or deployment, even though no explicit vulnerabilities are currently identified in the provided data.

Key Concerns

  • Missing nonce checks
  • Bundled library (TinyMCE)
Vulnerabilities
None known

NexIndex – Auto Table of Contents & SEO Links Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

NexIndex – Auto Table of Contents & SEO Links Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
1
45 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

SQL Query Safety

100% prepared1 total queries

Output Escaping

98% escaped46 total outputs
Attack Surface

NexIndex – Auto Table of Contents & SEO Links Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionadmin_menuadmin\class-nexindex-admin.php:6
actionadmin_initadmin\class-nexindex-admin.php:7
actionadmin_enqueue_scriptsadmin\class-nexindex-admin.php:8
actionenqueue_block_editor_assetsadmin\class-nexindex-admin.php:9
actionadmin_initadmin\class-nexindex-admin.php:10
filtermce_external_pluginsadmin\class-nexindex-admin.php:61
filtermce_buttons_2admin\class-nexindex-admin.php:62
actionplugins_loadednexindex.php:35
actionwp_enqueue_scriptspublic\class-nexindex-public.php:7
filterthe_contentpublic\class-nexindex-public.php:8
actionwp_footerpublic\class-nexindex-public.php:9
actionwp_body_openpublic\class-nexindex-public.php:10
Maintenance & Trust

NexIndex – Auto Table of Contents & SEO Links Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 8, 2025
PHP min version7.4
Downloads145

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

NexIndex – Auto Table of Contents & SEO Links Developer Profile

NexPlugin

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect NexIndex – Auto Table of Contents & SEO Links

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nexindex/admin/js/nexindex-editor.js/wp-content/plugins/nexindex/admin/js/nexindex-format.js/wp-content/plugins/nexindex/admin/js/nexindex-tinymce.js
Script Paths
/wp-content/plugins/nexindex/admin/js/nexindex-editor.js/wp-content/plugins/nexindex/admin/js/nexindex-format.js/wp-content/plugins/nexindex/admin/js/nexindex-tinymce.js
Version Parameters
nexindex-editor-js?ver=nexindex-format-js?ver=nexindex_buttons

HTML / DOM Fingerprints

CSS Classes
nex-tabsnex-tab-linknex-tab-contentnex-cardskin-selectorskin-itemskin-previewmock-glass+10 more
Data Attributes
data-nexindex-settings
JS Globals
window.nexindex_data
FAQ

Frequently Asked Questions about NexIndex – Auto Table of Contents & SEO Links