
byBrick Accordion Security & Risk Analysis
wordpress.org/plugins/bybrick-accordionA plugin that enables in-post open and close menus/accordions.
Is byBrick Accordion Safe to Use in 2026?
Use With Caution
Score 64/100byBrick Accordion has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The static analysis of the bybrick-accordion plugin v1.0 reveals a seemingly robust security posture from a code perspective. There are no identified dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. Furthermore, the plugin exhibits no file operations, external HTTP requests, or critical code signals like missing nonce or capability checks in its analyzed entry points, which are nonexistent. This suggests that the direct attack surface within the analyzed code is minimal and well-hardened against common code injection and data manipulation vulnerabilities.
However, the presence of one known and currently unpatched CVE for this plugin, specifically a medium severity Cross-Site Scripting (XSS) vulnerability, significantly elevates the risk. The static analysis, while thorough for the code provided, does not appear to have flagged the conditions leading to this historical vulnerability, implying the vulnerability might reside in an area not covered by the static analysis scope or that the analysis tools were not configured to detect this specific type of flaw. The fact that the last vulnerability was in 2025 suggests the plugin may not be actively maintained or that a patch was intended but not implemented, leaving users exposed.
In conclusion, while the current code appears clean and follows secure coding practices, the unpatched XSS vulnerability is a critical concern. The plugin's security is compromised by its vulnerability history, indicating a significant risk despite the positive findings in the static code analysis. Users should be extremely cautious and prioritize updating or replacing this plugin.
Key Concerns
- Unpatched medium severity CVE
byBrick Accordion Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
byBrick Accordion <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
byBrick Accordion Code Analysis
byBrick Accordion Attack Surface
WordPress Hooks 1
Maintenance & Trust
byBrick Accordion Maintenance & Trust
Maintenance Signals
Community Trust
byBrick Accordion Alternatives
Show Hide Accordion by MediaArt
show-hide-accordion-by-mediaart
Create collapse/expand sections and accordions via shortcodes (ma_collapse + legacy bg_collapse).
Read More & Accordion
expand-maker
Easily hide or reveal long content with Read More buttons, accordions, and popups. Streamline your WordPress site's layout while enhancing user e …
Lightweight Accordion
lightweight-accordion
Simple accordion for adding collapse elements to pages without affecting page load time. Includes Gutenberg block and shortcode for classic editor.
Meks Flexible Shortcodes
meks-flexible-shortcodes
Add some cool elements to your post/page content with flexible shortcodes.
Tabby Responsive Tabs
tabby-responsive-tabs
Create responsive tabs inside your posts, pages or custom post content by adding simple shortcodes inside the post editor.
byBrick Accordion Developer Profile
2 plugins · 130 total installs
How We Detect byBrick Accordion
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bybrick-accordion/style.cssHTML / DOM Fingerprints
accordion-titleaccordion-content<!-- Please define the title for the accordion -->id="bb_accordion_jQuery<div id="_title" class="accordion-title"></div><div style="display:none;" id="