
Supplyist TOC Block Security & Risk Analysis
wordpress.org/plugins/supplyist-toc-blockA simple Gutenberg block that automatically generates a nested table of contents from post headings.
Is Supplyist TOC Block Safe to Use in 2026?
Generally Safe
Score 100/100Supplyist TOC Block has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The `supplyist-toc-block` plugin v1.0.0 exhibits an excellent security posture based on the provided static analysis and vulnerability history. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the attack surface. Furthermore, the code demonstrates robust security practices, with no dangerous functions, all SQL queries utilizing prepared statements, and all output properly escaped. The lack of file operations, external HTTP requests, nonce checks, and capability checks, while contributing to a reduced attack surface, also means that there are no explicit security controls implemented for any potential entry points, should they exist and remain undiscovered by this analysis.
The plugin's vulnerability history is equally impressive, with zero recorded CVEs across all severity levels. This suggests a developer commitment to security or a lack of historical discovery of vulnerabilities. The complete absence of any taint analysis findings further strengthens this positive assessment.
In conclusion, based on the data provided, `supplyist-toc-block` v1.0.0 appears to be a very secure plugin. Its strengths lie in its minimal attack surface and adherence to secure coding practices in areas where code was analyzed. The primary, albeit minor, concern is the complete lack of capability checks and nonce checks, which, in conjunction with the zero entry points reported, could indicate an absence of security features rather than a deliberate security design. However, without known vulnerabilities or exploitable code paths identified, the overall risk is exceptionally low.
Key Concerns
- No capability checks found
- No nonce checks found
Supplyist TOC Block Security Vulnerabilities
Supplyist TOC Block Code Analysis
Output Escaping
Supplyist TOC Block Attack Surface
WordPress Hooks 2
Maintenance & Trust
Supplyist TOC Block Maintenance & Trust
Maintenance Signals
Community Trust
Supplyist TOC Block Alternatives
Digital Table of Contents
digital-table-of-contents
A powerful and customizable TOC plugin. Effortlessly navigate your content with advanced features and flexible styling.
Protos TOC Generator
protos-toc-generator
Auto-generates a floating or inline table of contents with anchor links based on headings in your post. Improves readability and SEO.
LuckyWP Table of Contents
luckywp-table-of-contents
Creates SEO-friendly table of contents for your posts/pages. Works automatically or manually (via shortcode, Gutenberg block or widget).
Rich Table of Contents
rich-table-of-content
RTOC is a table of contents generation plugin from Japan that allows anyone to easily create a table of contents. Equipped with the functions of the c …
Joli Table Of Contents
joli-table-of-contents
The Best Table of Contents Plugin for WordPress. User-friendly. Gutenberg Block. Fast & Highly customizable. Auto or manual insert.
Supplyist TOC Block Developer Profile
2 plugins · 0 total installs
How We Detect Supplyist TOC Block
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
data:text/javascript,HTML / DOM Fingerprints
ctb-tocctb-toc-titlectb-level-custom-tocidwindow.wp.blockswindow.wp.elementwindow.wp.i18n