
Accordion Slider Security & Risk Analysis
wordpress.org/plugins/accordion-sliderAccordion Slider is a responsive accordion plugin that offers Premium features for FREE, like animated layers, post content, full width layout.
Is Accordion Slider Safe to Use in 2026?
Generally Safe
Score 96/100Accordion Slider has a strong security track record. Known vulnerabilities have been patched promptly.
The accordion-slider plugin v1.9.14 exhibits a mixed security posture. While a significant portion of its SQL queries utilize prepared statements and output escaping is generally well-implemented, several concerning factors emerge. The presence of 14 unprotected entry points, including AJAX handlers and a REST API route, presents a substantial attack surface for unauthenticated or improperly authorized users. The use of `unserialize` is a known dangerous function that can lead to object injection vulnerabilities if not handled with extreme caution. Taint analysis reveals 4 high-severity flows with unsanitized paths, indicating potential for serious security issues if these flows are exposed to user input. The vulnerability history shows 3 past medium-severity CVEs, primarily related to Cross-site Scripting and Missing Authorization, which aligns with the identified unprotected entry points and the lack of robust authorization checks. The most recent vulnerability was in November 2025, suggesting a pattern of past issues that require attention. Overall, the plugin has strengths in data handling but weaknesses in access control and potential for code execution via dangerous functions and unsanitized data flows.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API route
- Use of dangerous function: unserialize
- High severity taint flows with unsanitized paths
- Past CVEs for XSS and Missing Authorization
- Limited capability checks
Accordion Slider Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Accordion Slider <= 1.9.13 - Authenticated (Contributor+) Stored Cross-Site Scripting
Accordion Slider <= 1.9.11 - Authenticted (Contributor+) Stored Cross-Site Scripting via HTML Attribute
Accordion Slider <= 1.9.6 - Missing Authorization to Notice Dismissal
Accordion Slider Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Accordion Slider Attack Surface
AJAX Handlers 28
REST API Routes 1
Shortcodes 3
WordPress Hooks 24
Maintenance & Trust
Accordion Slider Maintenance & Trust
Maintenance Signals
Community Trust
Accordion Slider Alternatives
Accordion and Accordion Slider
accordion-and-accordion-slider
Accordion and Accordion Slider - Responsive and Touch enabled accordion for WordPress Website. Also work with Gutenberg shortcode block.
Accordion FAQ – Compatible With All Page Builder (Elementor, Gutenberg)
responsive-accordion-and-collapse
Accordion And Collapse is the most easiest drag & drop accordion builder for WordPress. You can add multiple accordion and collapse with this.
Ditty – Responsive News Tickers, Sliders, and Lists
ditty-news-ticker
Ditty offers a range of content display options, including its signature news ticker and customizable layouts.
Ultimate Responsive Image Slider
ultimate-responsive-image-slider
Create stunning responsive sliders in minutes. Drag-and-drop builder, unlimited sliders, mobile-friendly & SEO optimized!
Accordions
accordions
Create sleek accordions, tabs, FAQs, and image accordions with a React builder featuring advanced styling, animations, OpenAI support, and customizati …
Accordion Slider Developer Profile
3 plugins · 6K total installs
How We Detect Accordion Slider
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/accordion-slider/public/css/style.css/wp-content/plugins/accordion-slider/public/css/lightslider.css/wp-content/plugins/accordion-slider/public/css/bootstrap.min.css/wp-content/plugins/accordion-slider/public/js/accordion-slider.js/wp-content/plugins/accordion-slider/public/js/modernizr.custom.js/wp-content/plugins/accordion-slider/public/js/jquery.mousewheel.min.js/wp-content/plugins/accordion-slider/public/js/jquery.easing.1.3.js/wp-content/plugins/accordion-slider/public/js/lightslider.min.js+1 more/wp-content/plugins/accordion-slider/public/js/accordion-slider.js/wp-content/plugins/accordion-slider/public/js/modernizr.custom.js/wp-content/plugins/accordion-slider/public/js/jquery.mousewheel.min.js/wp-content/plugins/accordion-slider/public/js/jquery.easing.1.3.js/wp-content/plugins/accordion-slider/public/js/lightslider.min.js/wp-content/plugins/accordion-slider/public/js/bootstrap.min.js/wp-content/plugins/accordion-slider/public/css/style.css?ver=/wp-content/plugins/accordion-slider/public/css/lightslider.css?ver=/wp-content/plugins/accordion-slider/public/css/bootstrap.min.css?ver=/wp-content/plugins/accordion-slider/public/js/accordion-slider.js?ver=/wp-content/plugins/accordion-slider/public/js/modernizr.custom.js?ver=/wp-content/plugins/accordion-slider/public/js/jquery.mousewheel.min.js?ver=/wp-content/plugins/accordion-slider/public/js/jquery.easing.1.3.js?ver=/wp-content/plugins/accordion-slider/public/js/lightslider.min.js?ver=/wp-content/plugins/accordion-slider/public/js/bootstrap.min.js?ver=HTML / DOM Fingerprints
bqw-accordion-sliderbqw-accordion-slider-panelbqw-accordion-slider-layer-wrapperbqw-accordion-slider-image-wrapperbqw-accordion-slider-text-wrapperbqw-accordion-slider-video-wrapperaccordion-slider-wraplSSlideWrapper+4 more<!-- Accordion Slider --><!-- The main accordion slider component --><!-- Slider Items --><!-- Slide -->+1 moredata-accordion-slider-iddata-panel-iddata-layer-iddata-layer-typedata-settingsbqwAccordionSliderBQW_Accordion_Slider_Block/wp-json/accordion-slider/v1/settings/wp-json/accordion-slider/v1/add-ons[accordion_slider[bqw_accordion_slider