
Shortcode Table of Contents Security & Risk Analysis
wordpress.org/plugins/shortcode-tocDisplay an automated table of contents via shortcode.
Is Shortcode Table of Contents Safe to Use in 2026?
Generally Safe
Score 85/100Shortcode Table of Contents has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The shortcode-toc plugin, version 1.0.3, exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and 100% proper output escaping are significant strengths. Furthermore, no external HTTP requests, file operations, or taint analysis issues were identified, indicating a well-contained and secure codebase. The plugin also has a clean vulnerability history with zero recorded CVEs, which is highly encouraging.
However, a notable concern is the complete lack of nonce checks and capability checks across all entry points. While the static analysis reported zero unprotected entry points (suggesting the single shortcode might not be directly exploitable without further context), the absence of these fundamental WordPress security mechanisms leaves it vulnerable to potential cross-site request forgery (CSRF) attacks if the shortcode's functionality is sensitive or can be manipulated to perform unintended actions. This omission represents a significant gap in defense against common web attack vectors.
In conclusion, shortcode-toc v1.0.3 demonstrates good coding practices in critical areas like SQL and output handling, and has a flawless security track record. Nevertheless, the missing nonce and capability checks introduce a significant risk that should be addressed by developers to ensure comprehensive security.
Key Concerns
- Missing nonce checks on all entry points
- Missing capability checks on all entry points
Shortcode Table of Contents Security Vulnerabilities
Shortcode Table of Contents Code Analysis
Output Escaping
Shortcode Table of Contents Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Shortcode Table of Contents Maintenance & Trust
Maintenance Signals
Community Trust
Shortcode Table of Contents Alternatives
GutenTOC – Advanced Table of Contents
gutentoc-advance-table-of-content
GutenTOC is an SEO-friendly Table of Contents builder block for the WordPress block editor. It scans headings in your content and automatically gene …
Easy Table of Contents
easy-table-of-contents
Adds a user friendly and fully automatic way to create and display a table of contents generated from the page content.
Table of Contents Plus
table-of-contents-plus
A powerful yet user friendly plugin that automatically creates a table of contents. Can also output a sitemap listing all pages and categories.
LuckyWP Table of Contents
luckywp-table-of-contents
Creates SEO-friendly table of contents for your posts/pages. Works automatically or manually (via shortcode, Gutenberg block or widget).
Rich Table of Contents
rich-table-of-content
RTOC is a table of contents generation plugin from Japan that allows anyone to easily create a table of contents. Equipped with the functions of the c …
Shortcode Table of Contents Developer Profile
3 plugins · 900 total installs
How We Detect Shortcode Table of Contents
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shortcode-toc/assets/vendor/js/anchorific.js/wp-content/plugins/shortcode-toc/assets/vendor/js/anchorific.jsshortcode-toc/1.0.3anchorific.js?ver=1.0.3HTML / DOM Fingerprints
shortcode-tocJCK_STOC_VERSION<div class="shortcode-toc"></div>