
Multipage Security & Risk Analysis
wordpress.org/plugins/sgr-nextpage-titlesOrder your posts in subpages: multipage posts will have a table of contents linking single subpages with their titles.
Is Multipage Safe to Use in 2026?
Generally Safe
Score 85/100Multipage has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The sgr-nextpage-titles plugin v1.5.12 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The plugin demonstrates good practices by avoiding dangerous functions, file operations, and external HTTP requests. Importantly, there are no known CVEs associated with this plugin, and its vulnerability history is clean, which suggests a commitment to security by the developers. The limited attack surface, consisting solely of one shortcode, is a positive sign, especially as it appears to have no unprotected entry points.
However, there are areas for improvement. The static analysis reveals that only 50% of SQL queries use prepared statements, and a concerning 42% of output is not properly escaped. While no critical or high severity taint flows were detected, the presence of unsanitized data in output could still lead to cross-site scripting (XSS) vulnerabilities if not handled carefully. The absence of capability checks on its single entry point (the shortcode) also raises a flag, as it implies that any logged-in user could potentially interact with the shortcode's functionality without specific permissions.
In conclusion, sgr-nextpage-titles v1.5.12 is a relatively low-risk plugin due to its lack of known vulnerabilities and minimal attack surface. However, the unescaped output and the lack of capability checks on the shortcode represent potential security weaknesses that should be addressed to further enhance its security.
Key Concerns
- SQL queries not fully prepared
- Significant amount of unescaped output
- No capability checks on shortcode
Multipage Security Vulnerabilities
Multipage Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Multipage Attack Surface
Shortcodes 1
WordPress Hooks 29
Maintenance & Trust
Multipage Maintenance & Trust
Maintenance Signals
Community Trust
Multipage Alternatives
LuckyWP Table of Contents
luckywp-table-of-contents
Creates SEO-friendly table of contents for your posts/pages. Works automatically or manually (via shortcode, Gutenberg block or widget).
Table Of Contents Block
table-of-contents-block
Automatically Add Table of Contents Block for your WordPress Posts & Pages
Heroic Table of Contents
heroic-table-of-contents
Heroic Table of Contents is the easiest way to add a table of contents to your site.
TOP Table Of Contents
top-table-of-contents
Easily creates SEO-friendly table of contents for your blog posts and pages. Offers both Auto and Manual Insert with highly customization options.
Table of Contents Creator
table-of-contents-creator
Table of Contents Creator automatically generates a highly customizable dynamic site wide table of contents that is always up-to-date.
Multipage Developer Profile
2 plugins · 1K total installs
How We Detect Multipage
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sgr-nextpage-titles/inc/mpp-template.phpHTML / DOM Fingerprints
<!-- wp:multipage/subpage<!-- /wp:multipage/subpage --><!--nextpage-->[nextpage<!-- wp:multipage/subpage