Table of Contents Generator – SmartTOC Lite Security & Risk Analysis

wordpress.org/plugins/smarttoc-lite

Create a clean, accessible Table of Contents — fast, customizable, and compatible with any theme or editor.

10 active installs v1.1.3 PHP 7.2+ WP 5.6+ Updated Feb 12, 2026
accessibilityblock-editorseotable-of-contentswordpress-toc
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Table of Contents Generator – SmartTOC Lite Safe to Use in 2026?

Generally Safe

Score 100/100

Table of Contents Generator – SmartTOC Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The smarttoc-lite v1.1.3 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. The presence of nonce and capability checks, along with the near-perfect output escaping (77%), indicates good development practices aimed at preventing common web vulnerabilities. Furthermore, the complete lack of any recorded vulnerabilities (CVEs) historically is a very positive sign, suggesting a history of secure development and maintenance.

However, a minor concern arises from the percentage of improperly escaped outputs. While the majority are properly escaped, the 23% that are not could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in those specific outputs. The analysis also shows no taint flows, which is excellent, but this is based on a total of 0 flows analyzed, meaning the depth of the taint analysis might be limited. The limited entry points (1 shortcode) are all considered protected, which is a significant strength.

In conclusion, smarttoc-lite v1.1.3 appears to be a secure plugin with a low risk profile. The strengths in code hygiene and historical vulnerability absence far outweigh the minor concern of imperfect output escaping. The plugin benefits from a small attack surface and robust authentication checks where applicable. Continued vigilance in ensuring all outputs are correctly escaped is recommended.

Key Concerns

  • Improperly escaped outputs detected
Vulnerabilities
None known

Table of Contents Generator – SmartTOC Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Table of Contents Generator – SmartTOC Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
25
85 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

77% escaped110 total outputs
Attack Surface

Table of Contents Generator – SmartTOC Lite Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[smart_toc] includes\class-smarttoc-lite.php:16
WordPress Hooks 8
actionadmin_menuincludes\admin-settings.php:11
actionadmin_initincludes\admin-settings.php:12
actionadmin_enqueue_scriptsincludes\class-smarttoc-lite.php:15
actionadd_meta_boxesincludes\class-smarttoc-lite.php:17
actionsave_postincludes\class-smarttoc-lite.php:18
actionwp_enqueue_scriptsincludes\class-smarttoc-lite.php:26
actionwp_headincludes\class-smarttoc-lite.php:27
filterthe_contentincludes\class-smarttoc-lite.php:28
Maintenance & Trust

Table of Contents Generator – SmartTOC Lite Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 12, 2026
PHP min version7.2
Downloads528

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Table of Contents Generator – SmartTOC Lite Developer Profile

SinergoData

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Table of Contents Generator – SmartTOC Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/smarttoc-lite/css/smarttoc-lite.css/wp-content/plugins/smarttoc-lite/js/smarttoc-lite.js
Script Paths
/wp-content/plugins/smarttoc-lite/js/smarttoc-lite.js/wp-content/plugins/smarttoc-lite/js/smarttoc-lite-admin.js
Version Parameters
smarttoc-lite/css/smarttoc-lite.css?ver=smarttoc-lite/js/smarttoc-lite.js?ver=smarttoc-lite/js/smarttoc-lite-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
smarttoc-lite-navsmarttoc-lite-nav__itemsmarttoc-lite-nav__item--level-smarttoc-lite-nav__linksmarttoc-lite-nav__child-indicatorsmarttoc-lite-nav__textsmarttoc-lite-nav__togglesmarttoc-lite-nav__toggle--collapsed+6 more
HTML Comments
<!-- START: SmartTOC Lite --><!-- END: SmartTOC Lite --><!-- SmartTOC Lite Meta Box -->
Data Attributes
data-smooth-scrolldata-exclude-hrefdata-hide-textdata-show-text
JS Globals
smarttocLiteOptions
Shortcode Output
[smart_toc]
FAQ

Frequently Asked Questions about Table of Contents Generator – SmartTOC Lite