
ROOTS-index Security & Risk Analysis
wordpress.org/plugins/roots-index*このプラグインはグーテンベルグの見出しブロックから目次を作成します
Is ROOTS-index Safe to Use in 2026?
Generally Safe
Score 92/100ROOTS-index has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The roots-index v1.0.0 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs, critical taint flows, dangerous functions, and SQL injection vulnerabilities is a significant positive indicator. The plugin also demonstrates good practices by exclusively using prepared statements for SQL queries and implementing nonce checks for its single entry point. The majority of output is properly escaped, further mitigating cross-site scripting (XSS) risks.
However, there are a few areas that warrant attention. The lack of capability checks on the shortcode handler is a concern. While the attack surface is small (only one shortcode), without proper capability checks, any authenticated user could potentially trigger the shortcode's functionality, which could lead to unintended consequences if the shortcode performs sensitive operations or displays privileged information. Furthermore, while only 77% of output is properly escaped, it's important to understand what the remaining 23% of unescaped output entails, as even a small percentage of improperly escaped output can still pose an XSS risk.
Overall, roots-index v1.0.0 appears to be a relatively secure plugin with a good track record. The primary area for improvement lies in implementing capability checks for its shortcode. Continued vigilance with security updates and monitoring for future vulnerabilities remains essential for any plugin.
Key Concerns
- Shortcode entry point lacks capability checks
- 23% of output is not properly escaped
ROOTS-index Security Vulnerabilities
ROOTS-index Release Timeline
ROOTS-index Code Analysis
Output Escaping
ROOTS-index Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
ROOTS-index Maintenance & Trust
Maintenance Signals
Community Trust
ROOTS-index Alternatives
Rich Table of Contents
rich-table-of-content
RTOC is a table of contents generation plugin from Japan that allows anyone to easily create a table of contents. Equipped with the functions of the c …
Table of Contents Plus
table-of-contents-plus
A powerful yet user friendly plugin that automatically creates a table of contents. Can also output a sitemap listing all pages and categories.
TOP Table Of Contents
top-table-of-contents
Easily creates SEO-friendly table of contents for your blog posts and pages. Offers both Auto and Manual Insert with highly customization options.
Extended Table of Contents (with nextpage support)
extended-table-of-contents-with-nextpage-support
This plugin automatically generates and inserts a table of contents (ToC) to your pages and posts, based on tags h1-h6. It can deal with nextpage-tag.
F70 Simple Table of Contents
f70-simple-table-of-contents
Display a table of contents in your posts by automatically generated from the headings. No Javascript code, simple to use.
ROOTS-index Developer Profile
1 plugin · 0 total installs
How We Detect ROOTS-index
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/roots-index/assets/css/roots-index-accordion.css/wp-content/plugins/roots-index/assets/css/roots-index-toc.css/wp-content/plugins/roots-index/assets/js/roots-index-accordion.js/wp-content/plugins/roots-index/assets/js/roots-index-toc.js/wp-content/plugins/roots-index/assets/js/roots-index-toc.js/wp-content/plugins/roots-index/assets/js/roots-index-accordion.jsroots-index-toc.js?ver=1.0roots-index-accordion.js?ver=1.0roots-index-accordion.css?ver=1.0roots-index-toc.css?ver=1.0HTML / DOM Fingerprints
roots-index-toctocData<div id="roots-index-toc"></div>