
Accordions – Responsive Accordion & FAQ Plugin for WordPress Security & Risk Analysis
wordpress.org/plugins/accordions-wpResponsive, lightweight, and fully customizable accordion plugin for WordPress. Perfect for FAQs, content organization, and improving user experience.
Is Accordions – Responsive Accordion & FAQ Plugin for WordPress Safe to Use in 2026?
Generally Safe
Score 96/100Accordions – Responsive Accordion & FAQ Plugin for WordPress has a strong security track record. Known vulnerabilities have been patched promptly.
The "accordions-wp" plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by employing prepared statements for all SQL queries and including a substantial number of nonce and capability checks, indicating an awareness of common WordPress security vulnerabilities. The absence of direct file operations and external HTTP requests further reduces potential attack vectors.
However, concerns arise from the static analysis results. While the total number of entry points is low, the presence of a taint flow with unsanitized paths, particularly one identified as high severity, is a significant risk. This suggests that user-supplied data is not being properly validated or neutralized before being used in a sensitive operation, potentially leading to cross-site scripting or other injection vulnerabilities.
The plugin's vulnerability history, with three previously disclosed medium-severity CVEs, all related to Cross-site Scripting, reinforces the concern raised by the taint analysis. Although there are currently no unpatched vulnerabilities, the recurring nature of XSS issues suggests a persistent weakness in input sanitization. The outdated bundled library (Select2 v3.4.5) also presents a minor, but nonetheless real, security concern as older versions often contain known vulnerabilities. The overall risk is moderate, with the high-severity taint flow being the most pressing issue.
Key Concerns
- High severity taint flow with unsanitized paths
- Bundled outdated library: Select2 v3.4.5
- 3 known medium severity CVEs historically
- 78% output escaping (22% unescaped)
Accordions – Responsive Accordion & FAQ Plugin for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Accordion <= 3.0.3 - Authenticated (Editor+) Stored Cross-Site Scripting
Accordion <= 2.6 - Authenticated (Editor+) Stored Cross-Site Scripting via accordion settings
Accordion <= 2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Accordions – Responsive Accordion & FAQ Plugin for WordPress Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Accordions – Responsive Accordion & FAQ Plugin for WordPress Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 66
Maintenance & Trust
Accordions – Responsive Accordion & FAQ Plugin for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Accordions – Responsive Accordion & FAQ Plugin for WordPress Alternatives
Smart Accordion
smart-accordion
Smart Accordion is an stylish and customizable tool to shape and display on your website a list of the most frequent customer questions with answers.
WP Accordions
wp-accordions
WP Accordions with font color, background color styling options and 100% resposinve.
Accordion Blocks
accordion-blocks
Gutenberg block for creating responsive accordion drop-downs.
Meks Flexible Shortcodes
meks-flexible-shortcodes
Add some cool elements to your post/page content with flexible shortcodes.
Gutena Accordion – Beautiful FAQ Accordion Block
gutena-accordion
Gutena Accordion is a WordPress Plugin which makes accordion dropdown creation really easy inside the block editor. Furthermore, it is very light weig …
Accordions – Responsive Accordion & FAQ Plugin for WordPress Developer Profile
19 plugins · 10K total installs
How We Detect Accordions – Responsive Accordion & FAQ Plugin for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/accordions-wp/css/responsive-accordion.css/wp-content/plugins/accordions-wp/css/style.css/wp-content/plugins/accordions-wp/js/responsive-accordion.min.js/wp-content/plugins/accordions-wp/admin/css/accordion-backend-admin.css/wp-content/plugins/accordions-wp/admin/js/accordion-backend-admin.js/wp-content/plugins/accordions-wp/admin/js/color-picker.js/wp-content/plugins/accordions-wp/js/responsive-accordion.min.js/wp-content/plugins/accordions-wp/admin/js/accordion-backend-admin.js/wp-content/plugins/accordions-wp/admin/js/color-picker.jsHTML / DOM Fingerprints
accordion-titleaccordion-detailstcpaccordiondata-accordion-idTCP_accordions_wordpress_table_body[tcpaccordion