
Collapsed Archives Security & Risk Analysis
wordpress.org/plugins/collapsed-archivesAdds a widget to display archive links using purely CSS-based collapsing.
Is Collapsed Archives Safe to Use in 2026?
Generally Safe
Score 85/100Collapsed Archives has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'collapsed-archives' v1.6 plugin exhibits a generally strong security posture, with no reported vulnerabilities in its history and a clean static analysis regarding dangerous functions, SQL injection, file operations, and external requests. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the attack surface, and the lack of any taint flows suggests that the plugin is not processing user-supplied data in a way that could lead to critical or high-severity vulnerabilities. This indicates good development practices in these areas.
However, a notable concern arises from the low percentage of properly escaped output (7%). With 29 total outputs and only 2 properly escaped, this suggests a significant risk of Cross-Site Scripting (XSS) vulnerabilities. While the plugin has no known CVEs, the high number of unescaped outputs presents a potential avenue for attackers to inject malicious scripts, especially if the plugin's outputs are rendered in user-facing contexts without further server-side sanitization. The absence of nonce and capability checks, while less concerning due to the limited attack surface, still represents a missed opportunity to enhance security further. Overall, while the plugin is not actively exploited or known to be vulnerable, the output escaping issue requires immediate attention to mitigate potential XSS risks.
Key Concerns
- Low output escaping percentage (7%)
- No nonce checks
- No capability checks
Collapsed Archives Security Vulnerabilities
Collapsed Archives Release Timeline
Collapsed Archives Code Analysis
SQL Query Safety
Output Escaping
Collapsed Archives Attack Surface
WordPress Hooks 2
Maintenance & Trust
Collapsed Archives Maintenance & Trust
Maintenance Signals
Community Trust
Collapsed Archives Alternatives
WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager
insert-headers-and-footers
Easily add code snippets in WordPress. Insert header & footer scripts, add PHP code snippets with conditional logic, insert ads pixel code, and more.
Code Snippets
code-snippets
An easy, clean, and simple way to enhance your site with code snippets.
Simple Custom CSS and JS
custom-css-js
Easily add Custom CSS or JS to your website with an awesome editor.
Insert Headers And Footers
wp-headers-and-footers
Include inline javascript, stylesheets, CSS code or anything you want in Header and Footer areas of your WordPress with ease.
Jetpack Boost – Website Speed, Performance and Critical CSS
jetpack-boost
Speed up your WordPress site with one-click optimizations like Page Cache, Critical CSS, and Image CDN to improve Core Web Vitals.
Collapsed Archives Developer Profile
2 plugins · 1K total installs
How We Detect Collapsed Archives
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/collapsed-archives/style.csscollapsed-archives/style.css?ver=HTML / DOM Fingerprints
collapsed-archivescollapsed-archives-trianglesdecadeyearid="archive-decade-id="archive-year-for="archive-decade-for="archive-year-<div class="collapsed-archives<input type="checkbox"<label for="