
Sticky TOC – Advance Table Of Contents Security & Risk Analysis
wordpress.org/plugins/sticky-toc-advance-table-of-contentsSticky TOC is a powerful Wordpress plugin for creating automatic Table Of Content. It scans headings through the post content automatically and create …
Is Sticky TOC – Advance Table Of Contents Safe to Use in 2026?
Generally Safe
Score 85/100Sticky TOC – Advance Table Of Contents has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "sticky-toc-advance-table-of-contents" v1.0.2 exhibits a generally strong security posture based on the provided static analysis. The complete absence of dangerous functions, SQL queries using prepared statements, file operations, and external HTTP requests is commendable. Furthermore, the lack of known CVEs and historical vulnerabilities suggests a commitment to security or minimal exposure. However, there are areas for improvement. The low percentage of properly escaped output (56%) is a significant concern, as it indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks on entry points, although the attack surface is currently small, leaves the plugin vulnerable if new AJAX or REST API endpoints are introduced without proper security measures. The limited taint analysis may not cover all potential complex attack vectors. Overall, while the plugin avoids common pitfalls like raw SQL or unauthenticated AJAX, the unescaped output and lack of comprehensive authorization checks on entry points warrant attention to mitigate potential XSS and privilege escalation risks.
Key Concerns
- Significant percentage of unescaped output
- No nonce checks on entry points
- No capability checks on entry points
Sticky TOC – Advance Table Of Contents Security Vulnerabilities
Sticky TOC – Advance Table Of Contents Code Analysis
Output Escaping
Sticky TOC – Advance Table Of Contents Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Sticky TOC – Advance Table Of Contents Maintenance & Trust
Maintenance Signals
Community Trust
Sticky TOC – Advance Table Of Contents Alternatives
List of Contents
list-of-contents
Automatically generate a list of contents/table of contents for your posts, pages, and custom post types. Compatible with page builders and plugins.
Digital Table of Contents
digital-table-of-contents
A powerful and customizable TOC plugin. Effortlessly navigate your content with advanced features and flexible styling.
Easy Table of Contents
easy-table-of-contents
Adds a user friendly and fully automatic way to create and display a table of contents generated from the page content.
Table of Contents Plus
table-of-contents-plus
A powerful yet user friendly plugin that automatically creates a table of contents. Can also output a sitemap listing all pages and categories.
LuckyWP Table of Contents
luckywp-table-of-contents
Creates SEO-friendly table of contents for your posts/pages. Works automatically or manually (via shortcode, Gutenberg block or widget).
Sticky TOC – Advance Table Of Contents Developer Profile
2 plugins · 100 total installs
How We Detect Sticky TOC – Advance Table Of Contents
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sticky-toc-advance-table-of-contents/assets/css/admin-style.css/wp-content/plugins/sticky-toc-advance-table-of-contents/assets/js/admin-script.js/wp-content/plugins/sticky-toc-advance-table-of-contents/assets/css/styles.css/wp-content/plugins/sticky-toc-advance-table-of-contents/assets/js/script.js/wp-content/plugins/sticky-toc-advance-table-of-contents/assets/js/admin-script.js/wp-content/plugins/sticky-toc-advance-table-of-contents/assets/js/script.jssticky-toc-advance-table-of-contents/assets/css/admin-style.css?ver=sticky-toc-advance-table-of-contents/assets/js/admin-script.js?ver=sticky-toc-advance-table-of-contents/assets/css/styles.css?ver=sticky-toc-advance-table-of-contents/assets/js/script.js?ver=HTML / DOM Fingerprints
wpig-admin-settingsSTOC[stoc]