
Supplyist TOC Block Security & Risk Analysis
wordpress.org/plugins/supplyist-toc-blockA simple Gutenberg block that automatically generates a nested table of contents from post headings.
Is Supplyist TOC Block Safe to Use in 2026?
Generally Safe
Score 100/100Supplyist TOC Block has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The `supplyist-toc-block` plugin v1.0.0 exhibits an excellent security posture based on the provided static analysis and vulnerability history. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the attack surface. Furthermore, the code demonstrates robust security practices, with no dangerous functions, all SQL queries utilizing prepared statements, and all output properly escaped. The lack of file operations, external HTTP requests, nonce checks, and capability checks, while contributing to a reduced attack surface, also means that there are no explicit security controls implemented for any potential entry points, should they exist and remain undiscovered by this analysis.
The plugin's vulnerability history is equally impressive, with zero recorded CVEs across all severity levels. This suggests a developer commitment to security or a lack of historical discovery of vulnerabilities. The complete absence of any taint analysis findings further strengthens this positive assessment.
In conclusion, based on the data provided, `supplyist-toc-block` v1.0.0 appears to be a very secure plugin. Its strengths lie in its minimal attack surface and adherence to secure coding practices in areas where code was analyzed. The primary, albeit minor, concern is the complete lack of capability checks and nonce checks, which, in conjunction with the zero entry points reported, could indicate an absence of security features rather than a deliberate security design. However, without known vulnerabilities or exploitable code paths identified, the overall risk is exceptionally low.
Key Concerns
- No capability checks found
- No nonce checks found
Supplyist TOC Block Security Vulnerabilities
Supplyist TOC Block Release Timeline
Supplyist TOC Block Code Analysis
Output Escaping
Supplyist TOC Block Attack Surface
WordPress Hooks 2
Maintenance & Trust
Supplyist TOC Block Maintenance & Trust
Maintenance Signals
Community Trust
Supplyist TOC Block Alternatives
Joli Table Of Contents
joli-table-of-contents
The best Table of Contents plugin for WordPress. Auto or manual insert, Gutenberg Block, beautiful themes, onboarding wizard, and deep customization.
Ajejey Smart Table of Contents
ajejey-smart-toc
Automatically generate a beautiful table of contents from your post/page headings with smooth scroll navigation.
Digital Table of Contents
digital-table-of-contents
A powerful and customizable TOC plugin. Effortlessly navigate your content with advanced features and flexible styling.
Protos TOC Generator
protos-toc-generator
Auto-generates a floating or inline table of contents with anchor links based on headings in your post. Improves readability and SEO.
SmoothTOC
smooth-toc
Automatically generates a Table of Contents for your posts and pages.
Supplyist TOC Block Developer Profile
2 plugins · 0 total installs
How We Detect Supplyist TOC Block
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
data:text/javascript,HTML / DOM Fingerprints
ctb-tocctb-toc-titlectb-level-custom-tocidwindow.wp.blockswindow.wp.elementwindow.wp.i18n