
Collapsing Archives Security & Risk Analysis
wordpress.org/plugins/collapsing-archivesThis plugin uses Javascript to dynamically expand or collapse the set of months for each year and posts for each month in the archive listing of your …
Is Collapsing Archives Safe to Use in 2026?
Generally Safe
Score 99/100Collapsing Archives has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "collapsing-archives" v3.0.8 presents a mixed security posture. On the positive side, static analysis reveals no identifiable attack surface through AJAX handlers, REST API routes, shortcodes, or cron events that are not properly authenticated or permission-checked. Furthermore, the plugin demonstrates good practices by exclusively using prepared statements for its SQL queries and having no external HTTP requests, reducing common attack vectors. However, there are significant concerns regarding output escaping, with only 78% of outputs being properly escaped, leaving potential for cross-site scripting vulnerabilities. The absence of nonce checks and capability checks for any potential entry points, though currently none are identified, is a notable gap in defense-in-depth. The plugin's vulnerability history, specifically a medium-severity CVE discovered very recently (2024-08-26) related to Cross-site Scripting, is a red flag that underscores the potential for exploitable flaws despite the current lack of identified critical issues in static analysis.
Key Concerns
- Output escaping is not comprehensive (78%)
- No nonce checks present
- No capability checks present
- Medium severity CVE in vulnerability history
Collapsing Archives Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Collapsing Archives <= 3.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Collapsing Archives Code Analysis
SQL Query Safety
Output Escaping
Collapsing Archives Attack Surface
WordPress Hooks 2
Maintenance & Trust
Collapsing Archives Maintenance & Trust
Maintenance Signals
Community Trust
Collapsing Archives Alternatives
Expanding Archives
expanding-archives
This plugin adds a new widget where you can view your old posts by expanding certain years and months.
Ultimate Tabbed Widgets
ultimate-tabbed-widgets
A plugin that allows you to create widget areas that can be turned into tabs or
WPB Widgets Accordion for WooCommerce
wpb-woocommerce-widgets-accordion
WPB Widgets Accordion for WooCommerce will allow you to show your widgets in an accordion.
ARCW Popover Addon
arcw-popover-addon
Popover Addon for Archives Calendar Widget
Folding Archives
folding-archives
A simple widget providing a customisable, animated dropdown menu to display archives.
Collapsing Archives Developer Profile
7 plugins · 7K total installs
How We Detect Collapsing Archives
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/collapsing-archives/collapsArchStyles.php/wp-content/plugins/collapsing-archives/collapsFunctions.js/wp-content/plugins/collapsing-archives/symbols.php/wp-content/plugins/collapsing-archives/collapsFunctions.jscollapsing-archives/style.css?ver=collapsing-archives/collapsArchStyles.php?ver=collapsing-archives/collapsFunctions.js?ver=collapsing-archives/symbols.php?ver=HTML / DOM Fingerprints
widget-titlecollapsArch/* These variables are part of the Collapsing Archives Plugin
* version: 3.0.8
* revision: $Id: collapsArch.php 3459499 2026-02-12 03:40:52Z robfelty $* Copyright 2008 Robert Felty (robfelty.com)widget-collapsArch-collapsItemswidgetRootaddExpandCollapseArch<h2 class='widget-title'>Archives</h2><ul id='widget-collapsArch-