
Author: António Andrade Security & Risk Analysis
wordpress.org/plugins/wp-table-of-paginated-contentsHandles naming of each post page through a TinyMCE button and produces a Table of Contents for the said post.
Is Author: António Andrade Safe to Use in 2026?
Generally Safe
Score 85/100Author: António Andrade has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-table-of-paginated-contents plugin v2.1 exhibits a generally good security posture, with no recorded vulnerabilities or critical taint analysis findings. The code analysis reveals a small attack surface, with only one shortcode as an entry point and no unprotected endpoints. Furthermore, all SQL queries utilize prepared statements, and there are no file operations or external HTTP requests, which are positive indicators. The plugin also implements capability checks, demonstrating an effort to restrict access to certain functionalities.
However, a significant concern arises from the complete lack of output escaping. With 11 total outputs and 0% properly escaped, this presents a high risk of Cross-Site Scripting (XSS) vulnerabilities. Attackers could potentially inject malicious scripts through the data displayed by the plugin, leading to session hijacking or other harmful actions. Additionally, the absence of nonce checks on the shortcode, if it handles user-supplied data or actions, could open the door to Cross-Site Request Forgery (CSRF) attacks, though the current analysis doesn't explicitly confirm this risk.
The plugin's clean vulnerability history is a strength, suggesting a history of responsible development or a lack of past exploitation. However, the critical flaw in output escaping overshadows this positive aspect. The plugin's strengths lie in its limited attack surface and secure database interactions. The primary weakness is the unescaped output, which must be addressed to mitigate XSS risks.
Key Concerns
- Unescaped output on all 11 outputs
- No nonce checks
Author: António Andrade Security Vulnerabilities
Author: António Andrade Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Author: António Andrade Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Author: António Andrade Maintenance & Trust
Maintenance Signals
Community Trust
Author: António Andrade Alternatives
Simple Paginated Posts
simple-paginated-posts
Generate table of contents for paginated posts
WP-PageNavi
wp-pagenavi
Adds a more advanced paging navigation interface.
LuckyWP Table of Contents
luckywp-table-of-contents
Creates SEO-friendly table of contents for your posts/pages. Works automatically or manually (via shortcode, Gutenberg block or widget).
Rich Table of Contents
rich-table-of-content
RTOC is a table of contents generation plugin from Japan that allows anyone to easily create a table of contents. Equipped with the functions of the c …
WP-Paginate
wp-paginate
WP-Paginate is a simple and flexible pagination plugin which provides users with better navigation on your WordPress site.
Author: António Andrade Developer Profile
2 plugins · 100 total installs
How We Detect Author: António Andrade
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-table-of-paginated-contents/wp-table-of-paginated-contents-ui.css/wp-content/plugins/wp-table-of-paginated-contents/wp-table-of-paginated-contents-ui.js/wp-content/plugins/wp-table-of-paginated-contents/wp-table-of-paginated-contents-tinyMCE-plugin.js/wp-content/plugins/wp-table-of-paginated-contents/wp-table-of-paginated-contents-tinyMCE-plugin.jswp-table-of-paginated-contents/wp-table-of-paginated-contents-ui.js?ver=wp-table-of-paginated-contents/wp-table-of-paginated-contents-ui.css?ver=HTML / DOM Fingerprints
table-of-paginated-contentscurrent_pagedata-wp-interactiveWPtopctinyMCE<select class='table-of-paginated-contents'<ul class='table-of-paginated-contents'><a href='' class='previous-link'>