Seo Friendly Table of Contents Security & Risk Analysis

wordpress.org/plugins/seo-friendly-table-of-contents

A simple seo friendly table of contents plugin that does not require editing in your themes source code.

100 active installs v2.0.1 PHP + WP 2.8.1+ Updated Aug 27, 2012
contentpageposttable-of-contentstoc
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Seo Friendly Table of Contents Safe to Use in 2026?

Generally Safe

Score 85/100

Seo Friendly Table of Contents has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "seo-friendly-table-of-contents" v2.0.1 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The code analysis reveals no dangerous functions, SQL injection vulnerabilities, or file operations, with all SQL queries utilizing prepared statements and all outputs being properly escaped. Furthermore, there are no external HTTP requests, indicating a limited external attack surface. The plugin also has a clean vulnerability history with zero recorded CVEs, suggesting a consistent track record of secure development and maintenance.

However, the absence of nonce and capability checks for its single shortcode presents a potential concern. While the shortcode is the only entry point identified and the overall attack surface is small, this lack of authentication could theoretically be exploited if the shortcode's functionality were to be manipulated in a way that impacts security. The taint analysis showing zero flows with unsanitized paths is a positive sign, but the lack of specific checks on the shortcode remains a minor weakness in an otherwise robust security profile.

In conclusion, the plugin is generally secure due to its clean code signals and lack of historical vulnerabilities. The primary area for improvement lies in implementing proper authorization mechanisms, such as nonce and capability checks, for its shortcode to further harden its security. Despite this minor concern, the plugin demonstrates good security practices.

Key Concerns

  • Missing nonce check on shortcode
  • Missing capability check on shortcode
Vulnerabilities
None known

Seo Friendly Table of Contents Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Seo Friendly Table of Contents Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries
Attack Surface

Seo Friendly Table of Contents Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[toc] seo-friendly-table-of-contents.php:48
WordPress Hooks 3
filterthe_contentseo-friendly-table-of-contents.php:29
actionwp_enqueue_scriptsseo-friendly-table-of-contents.php:32
actionadmin_menuseo-friendly-table-of-contents.php:195
Maintenance & Trust

Seo Friendly Table of Contents Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedAug 27, 2012
PHP min version
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Seo Friendly Table of Contents Developer Profile

Tobias Nyholm

5 plugins · 310 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Seo Friendly Table of Contents

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/seo-friendly-table-of-contents/style.css
Version Parameters
seo-friendly-table-of-contents/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
toc_titletoc
Data Attributes
id='toc_title'id='toc'
Shortcode Output
[toc levels=[toc levels=[toc levels=
FAQ

Frequently Asked Questions about Seo Friendly Table of Contents