
Table of Contents Creator Security & Risk Analysis
wordpress.org/plugins/table-of-contents-creatorTable of Contents Creator automatically generates a highly customizable dynamic site wide table of contents that is always up-to-date.
Is Table of Contents Creator Safe to Use in 2026?
Use With Caution
Score 63/100Table of Contents Creator has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "table-of-contents-creator" plugin v1.6.4.1 exhibits a concerning security posture, primarily due to significant weaknesses in output escaping and a history of unpatched vulnerabilities. While the static analysis shows a lack of direct attack surface through AJAX, REST API, shortcodes, or cron events, and no critical or high severity taint flows, the raw SQL queries and a substantial number of unescaped outputs represent significant potential risks. The absence of capability checks on entry points, although currently zero, is a general concern for plugins with any interactive elements.
The most alarming finding is the presence of a medium severity Cross-site Scripting (XSS) vulnerability that remains unpatched. This indicates a potential for attackers to inject malicious scripts into user sessions, which could lead to unauthorized actions, data theft, or website defacement. The fact that this vulnerability is from 2026 is unusual and might indicate a data error or a future disclosed vulnerability. The plugin's reliance on an outdated version of jQuery (v1.4.2) also poses a risk, as older libraries often contain known security flaws that could be exploited.
In conclusion, despite the absence of critical static analysis findings like dangerous functions or unsanitized paths, the plugin's security is severely undermined by its output escaping issues and the existence of an unpatched XSS vulnerability. The lack of proper escaping for 100% of its outputs is a major red flag, making it susceptible to various injection attacks if any user-supplied data reaches these output points. This plugin should be treated with extreme caution.
Key Concerns
- Unpatched Medium Severity CVE
- 100% of Outputs Not Properly Escaped
- 3 Raw SQL Queries (0% Prepared)
- Bundled Outdated Library (jQuery v1.4.2)
- 0% Capability Checks on Entry Points
Table of Contents Creator Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Table of Contents Creator <= 1.6.4.1 - Reflected Cross-Site Scripting
Table of Contents Creator Release Timeline
Table of Contents Creator Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Table of Contents Creator Attack Surface
WordPress Hooks 5
Maintenance & Trust
Table of Contents Creator Maintenance & Trust
Maintenance Signals
Community Trust
Table of Contents Creator Alternatives
LuckyWP Table of Contents
luckywp-table-of-contents
Creates SEO-friendly table of contents for your posts/pages. Works automatically or manually (via shortcode, Gutenberg block or widget).
Anik Smart Table of Contents
anik-smart-table-of-contents
A lightweight, SEO-friendly Table of Contents plugin that automatically generates TOC from your headings with smooth scroll and collapsible features.
Heroic Table of Contents
heroic-table-of-contents
Heroic Table of Contents is the easiest way to add a table of contents to your site.
TOP Table Of Contents
top-table-of-contents
Easily creates SEO-friendly table of contents for your blog posts and pages. Offers both Auto and Manual Insert with highly customization options.
F70 Simple Table of Contents
f70-simple-table-of-contents
Display a table of contents in your posts by automatically generated from the headings. No Javascript code, simple to use.
Table of Contents Creator Developer Profile
2 plugins · 700 total installs
How We Detect Table of Contents Creator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/table-of-contents-creator/tocc.css/wp-content/plugins/table-of-contents-creator/js/tocc.jswp-content/plugins/table-of-contents-creator/js/tocc.jstable-of-contents-creator/tocc.css?ver=table-of-contents-creator/js/tocc.js?ver=HTML / DOM Fingerprints
<!-- toc-creator -->