
Bellows Accordion Menu Security & Risk Analysis
wordpress.org/plugins/bellows-accordion-menuA flexible and robust accordion menu plugin
Is Bellows Accordion Menu Safe to Use in 2026?
Generally Safe
Score 98/100Bellows Accordion Menu has a strong security track record. Known vulnerabilities have been patched promptly.
The bellows-accordion-menu plugin v1.4.4 exhibits a mixed security posture. While it demonstrates good practices by using prepared statements for all SQL queries and avoiding file operations and external HTTP requests, there are significant concerns regarding output escaping and the absence of nonces and capability checks on its entry points. The static analysis reveals a substantial number of output points (80) with a concerningly low percentage (36%) being properly escaped, indicating a high potential for Cross-Site Scripting (XSS) vulnerabilities. The complete lack of nonce checks across its entry points, coupled with only one instance of a capability check, suggests that many of its functionalities could be manipulated by unauthenticated or low-privileged users. The vulnerability history shows a past pattern of two medium severity CVEs, both related to XSS, which reinforces the static analysis findings and highlights a recurring weakness. Although there are no currently unpatched vulnerabilities, the historical pattern and the static analysis results concerning output escaping and lack of robust authentication/authorization controls point to a plugin that requires careful attention to mitigate potential risks.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks on entry points
- Limited capability checks on entry points
- History of medium severity XSS vulnerabilities
Bellows Accordion Menu Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Bellows Accordion Menu <= 1.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Bellows Accordion Menu <= 1.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Bellows Accordion Menu Code Analysis
Output Escaping
Bellows Accordion Menu Attack Surface
Shortcodes 5
WordPress Hooks 31
Maintenance & Trust
Bellows Accordion Menu Maintenance & Trust
Maintenance Signals
Community Trust
Bellows Accordion Menu Alternatives
WP Widget in Navigation
wp-widget-in-navigation
Put your Widget in Navigation easily!
Menubar Widgets
menubar-widgets
A standard wordpress plugin that helps you add multiple widgets to navigation menu item.
Page Menus Widget
page-menus-widget
Menu with Page Assignment Widget
Easy Accordion Menu
easy-accordion-menu
Плагин Easy Accordion Menu позволяет организовать на вашем сайте простое и элегантное аккордеон меню (раскрывающееся меню).
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Bellows Accordion Menu Developer Profile
6 plugins · 126K total installs
How We Detect Bellows Accordion Menu
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bellows-accordion-menu/css/bellows-accordion-menu.css/wp-content/plugins/bellows-accordion-menu/css/bellows-tooltip.css/wp-content/plugins/bellows-accordion-menu/js/bellows-accordion-menu.js/wp-content/plugins/bellows-accordion-menu/js/jquery.bxslider.min.js/wp-content/plugins/bellows-accordion-menu/js/isotope.pkgd.min.js/wp-content/plugins/bellows-accordion-menu/js/masonry.pkgd.min.js/wp-content/plugins/bellows-accordion-menu/js/imagesloaded.pkgd.min.js/wp-content/plugins/bellows-accordion-menu/js/waypoints.min.js+1 more/wp-content/plugins/bellows-accordion-menu/js/jquery.bxslider.min.js/wp-content/plugins/bellows-accordion-menu/js/isotope.pkgd.min.js/wp-content/plugins/bellows-accordion-menu/js/masonry.pkgd.min.js/wp-content/plugins/bellows-accordion-menu/js/imagesloaded.pkgd.min.js/wp-content/plugins/bellows-accordion-menu/js/waypoints.min.js/wp-content/plugins/bellows-accordion-menu/js/bellows-animation.js+1 morebellows-accordion-menu/css/bellows-accordion-menu.css?ver=bellows-accordion-menu/css/bellows-tooltip.css?ver=bellows-accordion-menu/js/jquery.bxslider.min.js?ver=bellows-accordion-menu/js/isotope.pkgd.min.js?ver=bellows-accordion-menu/js/masonry.pkgd.min.js?ver=bellows-accordion-menu/js/imagesloaded.pkgd.min.js?ver=bellows-accordion-menu/js/waypoints.min.js?ver=bellows-accordion-menu/js/bellows-animation.js?ver=bellows-accordion-menu/js/bellows-accordion-menu.js?ver=HTML / DOM Fingerprints
bellows-containerbellows-accordion-menu-wrapbellows-sectionbellows-titlebellows-contentbellows-tooltip-triggerbellows-tooltipbellows-tooltip-arrow+8 more<!-- Bellows Accordion Menu --><!-- Bellows Settings Menu --><!-- Bellows Section --><!-- Bellows Title -->+1 moredata-bellows-iddata-bellows-animationdata-bellows-speeddata-bellows-pausedata-bellows-easingdata-bellows-controls+4 morebellowsAccordion