
Table of contents Maker Security & Risk Analysis
wordpress.org/plugins/toc-makerTable of contents Maker automatically creates a table of contents from headings.
Is Table of contents Maker Safe to Use in 2026?
Generally Safe
Score 92/100Table of contents Maker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "toc-maker" plugin v0.9.2 exhibits a generally strong security posture based on the provided static analysis. The absence of any known CVEs and the plugin's clean vulnerability history are positive indicators. The code analysis shows a commendable adherence to security best practices, with no dangerous functions, no direct SQL queries (all use prepared statements), and a very high percentage of properly escaped output. The presence of nonce and capability checks, while only one each, suggests an awareness of authentication and authorization mechanisms. The limited attack surface with no apparent unprotected entry points further strengthens this assessment.
However, the taint analysis reveals a minor concern: two flows with unsanitized paths. While these are not flagged as critical or high severity, unsanitized paths can sometimes be exploited in specific contexts, especially if they interact with file operations or external requests, which are not present here. The absence of any file operations or external HTTP requests is a significant positive. The plugin also lacks bundled libraries, eliminating risks associated with outdated dependencies.
In conclusion, "toc-maker" v0.9.2 appears to be a relatively secure plugin. The primary area for improvement is addressing the identified unsanitized paths, even though they haven't manifested as exploitable vulnerabilities. The plugin's clean history and robust coding practices for SQL and output escaping are strong points. The overall security is good, with only a minor area for enhancement.
Key Concerns
- Flows with unsanitized paths
Table of contents Maker Security Vulnerabilities
Table of contents Maker Release Timeline
Table of contents Maker Code Analysis
Output Escaping
Data Flow Analysis
Table of contents Maker Attack Surface
WordPress Hooks 7
Maintenance & Trust
Table of contents Maker Maintenance & Trust
Maintenance Signals
Community Trust
Table of contents Maker Alternatives
No alternatives data available yet.
Table of contents Maker Developer Profile
5 plugins · 330 total installs
How We Detect Table of contents Maker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/toc-maker/assets/css/front/toc.min.css/wp-content/plugins/toc-maker/assets/css/skin//wp-content/plugins/toc-maker/assets/css/admin/admin.min.css/wp-content/plugins/toc-maker/assets/js/admin/admin.min.js/wp-content/plugins/toc-maker/assets/js/admin/admin.min.jstoc-maker/assets/css/front/toc.min.css?ver=toc-maker/assets/css/skin/toc-maker/assets/css/admin/admin.min.css?ver=toc-maker/assets/js/admin/admin.min.js?ver=HTML / DOM Fingerprints
toc_maker_skinadmin_zipang_translations