
Content Accordin Security & Risk Analysis
wordpress.org/plugins/caccordinThis plugin is used for content accordion tab.
Is Content Accordin Safe to Use in 2026?
Generally Safe
Score 85/100Content Accordin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "caccordin" v1.0 plugin exhibits a generally strong security posture, with no known vulnerabilities or critical code signals indicating immediate risks. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. The plugin also demonstrates good practices by using prepared statements for all SQL queries and including capability checks on some entry points. However, the lack of nonce checks and only 50% of output being properly escaped present potential areas of concern.
The static analysis reveals a small attack surface with only one shortcode identified as an entry point, and this entry point appears to be unprotected. While there are no identified taint flows or critical code signals, the lack of nonces on the shortcode could theoretically be exploited if the shortcode itself performs any sensitive actions that are not adequately secured by capability checks. The limited output escaping suggests that some user-supplied data, if processed by the shortcode, might not be rendered safely, potentially leading to cross-site scripting (XSS) vulnerabilities.
Given the plugin's clean vulnerability history, it suggests that it has been developed with security in mind. The strengths lie in its limited external interactions and secure database practices. The weaknesses, however, revolve around the potential for XSS due to incomplete output escaping and the absence of nonce protection on its single entry point, which could be a target if not carefully implemented.
Key Concerns
- Shortcode with no nonce checks
- 50% of output not properly escaped
Content Accordin Security Vulnerabilities
Content Accordin Code Analysis
Output Escaping
Content Accordin Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Content Accordin Maintenance & Trust
Maintenance Signals
Community Trust
Content Accordin Alternatives
No alternatives data available yet.
Content Accordin Developer Profile
1 plugin · 10 total installs
How We Detect Content Accordin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/caccordin/js/caccordion.js/wp-content/plugins/caccordin/images/accordion_slope.jpg/wp-content/plugins/caccordin/images/accordion_arrow_side.png/wp-content/plugins/caccordin/images/accordion_arrow.png/wp-content/plugins/caccordin/js/editor_plugin.js/wp-content/plugins/caccordin/js/caccordion.js/wp-content/plugins/caccordin/js/editor_plugin.jsHTML / DOM Fingerprints
caccordion_containercaccordion_titlecaccordion_arrowcaccordion_arrow_sidecaccordion_contentcaccordin_div_hiddenid="caccordion_title"id="caccordion_content"id="caccordion_submit"id="caccordoin-title"tinyMCE[caccordion]