
Rich Table of Contents Security & Risk Analysis
wordpress.org/plugins/rich-table-of-contentRTOC is a table of contents generation plugin from Japan that allows anyone to easily create a table of contents. Equipped with the functions of the c …
Is Rich Table of Contents Safe to Use in 2026?
Generally Safe
Score 98/100Rich Table of Contents has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin 'rich-table-of-content' v1.4.3 exhibits a mixed security posture. While it demonstrates good practices by using prepared statements for all SQL queries and having no file operations or external HTTP requests, significant concerns arise from its output escaping and vulnerability history. The static analysis reveals a very low percentage (18%) of properly escaped outputs, indicating a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. Although no critical or high severity taint flows were identified in this specific version's static analysis, the history of two medium severity CVEs, specifically related to missing authorization and XSS, combined with the poor output escaping, suggests a recurring pattern of input sanitization and authorization weaknesses.
Key Concerns
- Low output escaping percentage (18%)
- History of 2 medium severity CVEs
- Vulnerability history indicates recurring XSS and authorization issues
Rich Table of Contents Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Rich Table of Contents <= 1.4.0 - Missing Authorization
Rich Table of Contents <= 1.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Rich Table of Contents Code Analysis
Output Escaping
Data Flow Analysis
Rich Table of Contents Attack Surface
Shortcodes 1
WordPress Hooks 29
Maintenance & Trust
Rich Table of Contents Maintenance & Trust
Maintenance Signals
Community Trust
Rich Table of Contents Alternatives
Table of Contents Plus
table-of-contents-plus
A powerful yet user friendly plugin that automatically creates a table of contents. Can also output a sitemap listing all pages and categories.
TOP Table Of Contents
top-table-of-contents
Easily creates SEO-friendly table of contents for your blog posts and pages. Offers both Auto and Manual Insert with highly customization options.
Extended Table of Contents (with nextpage support)
extended-table-of-contents-with-nextpage-support
This plugin automatically generates and inserts a table of contents (ToC) to your pages and posts, based on tags h1-h6. It can deal with nextpage-tag.
F70 Simple Table of Contents
f70-simple-table-of-contents
Display a table of contents in your posts by automatically generated from the headings. No Javascript code, simple to use.
CC-TOC
cc-toc
This plugin automatically creates a table of contents based on html headings in content.
Rich Table of Contents Developer Profile
1 plugin · 20K total installs
How We Detect Rich Table of Contents
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rich-table-of-content/css/rtoc.css/wp-content/plugins/rich-table-of-content/js/rtoc.js/wp-content/plugins/rich-table-of-content/css/rtoc.css?ver=/wp-content/plugins/rich-table-of-content/js/rtoc.js?ver=HTML / DOM Fingerprints
rtoc_bodyrtoc_contentrtoc_titlertoc_list_h2rtoc_list_h3rtoc_back_buttondata-text-colordata-title-colordata-back-colordata-border-colordata-h2-colordata-h3-colorrtoc