Supplyist TOC Block Security & Risk Analysis

wordpress.org/plugins/supplyist-toc-block

A simple Gutenberg block that automatically generates a nested table of contents from post headings.

0 active installs v1.0.0 PHP 7.4+ WP 6.0+ Updated Mar 10, 2026
gutenberg-blockheadingsnavigationtable-of-contentstoc
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Supplyist TOC Block Safe to Use in 2026?

Generally Safe

Score 100/100

Supplyist TOC Block has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 25d ago
Risk Assessment

The `supplyist-toc-block` plugin v1.0.0 exhibits an excellent security posture based on the provided static analysis and vulnerability history. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the attack surface. Furthermore, the code demonstrates robust security practices, with no dangerous functions, all SQL queries utilizing prepared statements, and all output properly escaped. The lack of file operations, external HTTP requests, nonce checks, and capability checks, while contributing to a reduced attack surface, also means that there are no explicit security controls implemented for any potential entry points, should they exist and remain undiscovered by this analysis.

The plugin's vulnerability history is equally impressive, with zero recorded CVEs across all severity levels. This suggests a developer commitment to security or a lack of historical discovery of vulnerabilities. The complete absence of any taint analysis findings further strengthens this positive assessment.

In conclusion, based on the data provided, `supplyist-toc-block` v1.0.0 appears to be a very secure plugin. Its strengths lie in its minimal attack surface and adherence to secure coding practices in areas where code was analyzed. The primary, albeit minor, concern is the complete lack of capability checks and nonce checks, which, in conjunction with the zero entry points reported, could indicate an absence of security features rather than a deliberate security design. However, without known vulnerabilities or exploitable code paths identified, the overall risk is exceptionally low.

Key Concerns

  • No capability checks found
  • No nonce checks found
Vulnerabilities
None known

Supplyist TOC Block Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Supplyist TOC Block Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped6 total outputs
Attack Surface

Supplyist TOC Block Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioninitsupplyist-toc-block.php:71
filterthe_contentsupplyist-toc-block.php:192
Maintenance & Trust

Supplyist TOC Block Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 10, 2026
PHP min version7.4
Downloads73

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Supplyist TOC Block Developer Profile

suppress

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Supplyist TOC Block

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
data:text/javascript,

HTML / DOM Fingerprints

CSS Classes
ctb-tocctb-toc-titlectb-level-custom-toc
Data Attributes
id
JS Globals
window.wp.blockswindow.wp.elementwindow.wp.i18n
FAQ

Frequently Asked Questions about Supplyist TOC Block