Sticky TOC – Advance Table Of Contents Security & Risk Analysis

wordpress.org/plugins/sticky-toc-advance-table-of-contents

Sticky TOC is a powerful Wordpress plugin for creating automatic Table Of Content. It scans headings through the post content automatically and create …

90 active installs v1.0.2 PHP + WP 3.5+ Updated Dec 9, 2022
fixed-tocliststicky-toctable-of-contentstoc
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Sticky TOC – Advance Table Of Contents Safe to Use in 2026?

Generally Safe

Score 85/100

Sticky TOC – Advance Table Of Contents has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The plugin "sticky-toc-advance-table-of-contents" v1.0.2 exhibits a generally strong security posture based on the provided static analysis. The complete absence of dangerous functions, SQL queries using prepared statements, file operations, and external HTTP requests is commendable. Furthermore, the lack of known CVEs and historical vulnerabilities suggests a commitment to security or minimal exposure. However, there are areas for improvement. The low percentage of properly escaped output (56%) is a significant concern, as it indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks on entry points, although the attack surface is currently small, leaves the plugin vulnerable if new AJAX or REST API endpoints are introduced without proper security measures. The limited taint analysis may not cover all potential complex attack vectors. Overall, while the plugin avoids common pitfalls like raw SQL or unauthenticated AJAX, the unescaped output and lack of comprehensive authorization checks on entry points warrant attention to mitigate potential XSS and privilege escalation risks.

Key Concerns

  • Significant percentage of unescaped output
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Sticky TOC – Advance Table Of Contents Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Sticky TOC – Advance Table Of Contents Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
28
36 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

56% escaped64 total outputs
Attack Surface

Sticky TOC – Advance Table Of Contents Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[stoc] sticky-toc-advance-table-of-contents.php:37
WordPress Hooks 9
actionadmin_enqueue_scriptsincludes\class.settings-api.php:20
actionadmin_initincludes\wpig-settings.php:29
actionadmin_menuincludes\wpig-settings.php:30
actionplugin_loadedsticky-toc-advance-table-of-contents.php:34
actionwp_enqueue_scriptssticky-toc-advance-table-of-contents.php:35
actionadmin_enqueue_scriptssticky-toc-advance-table-of-contents.php:36
filterthe_contentsticky-toc-advance-table-of-contents.php:38
filterthe_contentsticky-toc-advance-table-of-contents.php:39
actionwp_headsticky-toc-advance-table-of-contents.php:40
Maintenance & Trust

Sticky TOC – Advance Table Of Contents Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedDec 9, 2022
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings2
Active installs90
Developer Profile

Sticky TOC – Advance Table Of Contents Developer Profile

Ahmad Derar

2 plugins · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sticky TOC – Advance Table Of Contents

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sticky-toc-advance-table-of-contents/assets/css/admin-style.css/wp-content/plugins/sticky-toc-advance-table-of-contents/assets/js/admin-script.js/wp-content/plugins/sticky-toc-advance-table-of-contents/assets/css/styles.css/wp-content/plugins/sticky-toc-advance-table-of-contents/assets/js/script.js
Script Paths
/wp-content/plugins/sticky-toc-advance-table-of-contents/assets/js/admin-script.js/wp-content/plugins/sticky-toc-advance-table-of-contents/assets/js/script.js
Version Parameters
sticky-toc-advance-table-of-contents/assets/css/admin-style.css?ver=sticky-toc-advance-table-of-contents/assets/js/admin-script.js?ver=sticky-toc-advance-table-of-contents/assets/css/styles.css?ver=sticky-toc-advance-table-of-contents/assets/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpig-admin-settings
JS Globals
STOC
Shortcode Output
[stoc]
FAQ

Frequently Asked Questions about Sticky TOC – Advance Table Of Contents