Collapse It – Show More/Less Expand Button Security & Risk Analysis

wordpress.org/plugins/collapse-it

A Gutenberg block to collapse/expand content with fade effect, customizable height, and auto-hide when empty.

40 active installs v1.0.0 PHP + WP 5.8+ Updated Sep 4, 2025
collapseexpandfadegutenbergshow-more
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Collapse It – Show More/Less Expand Button Safe to Use in 2026?

Generally Safe

Score 100/100

Collapse It – Show More/Less Expand Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The "collapse-it" v1.0.0 plugin exhibits an exceptionally strong security posture based on the provided static analysis and vulnerability history. The absence of any identified attack surface points, dangerous functions, raw SQL queries, or output escaping issues is a significant strength. Furthermore, the plugin demonstrates robust security practices by not performing file operations or external HTTP requests, and by not bundling any external libraries, which are common sources of vulnerabilities. The lack of any recorded vulnerabilities, past or present, further reinforces its secure design.

While the static analysis indicates a near-perfect security implementation, it's important to note that the analysis reports zero flows analyzed by the taint analysis. This might mean the tool was unable to analyze certain parts of the code, or that the plugin's functionality is extremely minimal and truly has no complex data flows. The complete absence of nonce and capability checks across all potential entry points is a notable omission. Although the reported attack surface is zero, if any functionality were to be added in the future without proper authentication checks, it could introduce significant risks.

In conclusion, "collapse-it" v1.0.0 appears to be a highly secure plugin, with its developers adhering to excellent coding practices. The lack of any historical vulnerabilities and the clean static analysis report are commendable. The only potential area for improvement, given the current data, would be to ensure that any future feature additions are implemented with appropriate nonce and capability checks to maintain this high level of security.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
  • No taint flows analyzed
Vulnerabilities
None known

Collapse It – Show More/Less Expand Button Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Collapse It – Show More/Less Expand Button Release Timeline

v1.0.1
v1.0
Code Analysis
Analyzed Mar 16, 2026

Collapse It – Show More/Less Expand Button Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Collapse It – Show More/Less Expand Button Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actioninitcollapse-it.php:27
Maintenance & Trust

Collapse It – Show More/Less Expand Button Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 4, 2025
PHP min version
Downloads874

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Collapse It – Show More/Less Expand Button Developer Profile

DashboardTeam

1 plugin · 40 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Collapse It – Show More/Less Expand Button

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/collapse-it/build/index.js
Script Paths
/wp-content/plugins/collapse-it/build/index.js

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Collapse It – Show More/Less Expand Button