collexpander Security & Risk Analysis

wordpress.org/plugins/collexpander

The Collexpander WordPress plugin allows you to hide or show selected text content dynamically with a toggle button.

0 active installs v1.0.0 PHP + WP 6.8+ Updated Oct 13, 2025
collapseexpandhideshow
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is collexpander Safe to Use in 2026?

Generally Safe

Score 100/100

collexpander has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The collexpander v1.0.0 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and 100% proper output escaping are excellent security practices. Furthermore, the plugin successfully implements nonce and capability checks where appropriate, and has no recorded vulnerabilities, including CVEs. The limited attack surface, consisting solely of two shortcodes, further contributes to its secure design. There are no identified critical or high severity taint flows, indicating that user-supplied data is handled securely. The plugin's clean record and robust code signals suggest it is well-developed from a security perspective. The overall assessment is that the plugin presents a very low security risk.

Vulnerabilities
None known

collexpander Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

collexpander Release Timeline

v1.0.0Current
Code Analysis
Analyzed Mar 17, 2026

collexpander Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
21 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped21 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
hidden_stuff_menu_options (admin\class-hidden-stuff-admin.php:122)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

collexpander Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[collexpander-show-content] public\class-hidden-stuff-public.php:109
[collexpander-hide-content] public\class-hidden-stuff-public.php:110
WordPress Hooks 7
actionadmin_menuadmin\class-hidden-stuff-admin.php:55
actionadmin_enqueue_scriptsincludes\class-hidden-stuff.php:165
actionadmin_enqueue_scriptsincludes\class-hidden-stuff.php:166
actioninitincludes\class-hidden-stuff.php:181
actionwp_enqueue_scriptsincludes\class-hidden-stuff.php:182
actionwp_enqueue_scriptsincludes\class-hidden-stuff.php:183
actionplugins_loadedpublic\class-hidden-stuff-public.php:56
Maintenance & Trust

collexpander Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 13, 2025
PHP min version
Downloads201

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

collexpander Developer Profile

liaison

6 plugins · 0 total installs

98
trust score
Avg Security Score
97/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect collexpander

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/collexpander/js/collexpander.js/wp-content/plugins/collexpander/css/collexpander.css
Script Paths
/wp-content/plugins/collexpander/js/collexpander.js
Version Parameters
collexpander/js/collexpander.js?ver=collexpander/css/collexpander.css?ver=

HTML / DOM Fingerprints

CSS Classes
collexpander-toggle
Data Attributes
data-collexpander-targetdata-collexpander-toggle
JS Globals
collexpander
Shortcode Output
<span class="collexpander-toggle">
FAQ

Frequently Asked Questions about collexpander