
Read More & Accordion Security & Risk Analysis
wordpress.org/plugins/expand-makerEasily hide or reveal long content with Read More buttons, accordions, and popups. Streamline your WordPress site's layout while enhancing user e …
Is Read More & Accordion Safe to Use in 2026?
Generally Safe
Score 92/100Read More & Accordion has a strong security track record. Known vulnerabilities have been patched promptly.
The "expand-maker" plugin v3.5.7 exhibits a generally positive security posture with robust practices in place, such as a high percentage of prepared SQL statements and properly escaped output. The absence of critical or high severity taint flows and the complete lack of unprotected entry points (AJAX, REST API) are strong indicators of good development hygiene. Furthermore, the plugin effectively utilizes nonce and capability checks, which are crucial for preventing unauthorized actions. The inclusion of well-known bundled libraries like Select2 and TinyMCE is also common and not inherently a security concern unless those libraries themselves have known, unpatched vulnerabilities.
However, the plugin's vulnerability history presents a significant area of concern. With a total of 4 known CVEs, including 2 high and 2 medium severity vulnerabilities, the plugin has a track record of security weaknesses. The common vulnerability types (CSRF, Missing Authorization, Deserialization) suggest potential flaws in how user input is handled and validated, particularly in authenticated contexts. While there are no currently unpatched vulnerabilities, the historical pattern indicates that this plugin has been susceptible to serious issues, requiring continuous vigilance and prompt updating by users.
In conclusion, while the current version of "expand-maker" demonstrates improved static code security with no immediate critical flaws identified in the analysis, its past vulnerability landscape warrants caution. Users should be aware of the plugin's history and ensure they are always running the latest version. The presence of bundled libraries is a minor consideration, but the historical CVEs represent a more substantial risk that requires ongoing monitoring and timely patching by the plugin developers to maintain user trust and security.
Key Concerns
- Past high severity vulnerabilities (2)
- Past medium severity vulnerabilities (2)
- Bundled libraries (Select2, TinyMCE)
Read More & Accordion Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Read More & Accordion <= 3.5.5.1 - Missing Authorization
Read More & Accordion <= 3.4.7 - Cross-Site Request Forgery to Local File Inclusion
Read More & Accordion <= 3.4.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary 'Read More' Post Deletion
Read More & Accordion <= 3.2.6.1 - Authenticated (Administrator+) PHP Object Injection
Read More & Accordion Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Read More & Accordion Attack Surface
AJAX Handlers 12
Shortcodes 3
WordPress Hooks 38
Maintenance & Trust
Read More & Accordion Maintenance & Trust
Maintenance Signals
Community Trust
Read More & Accordion Alternatives
Collapse Magic
collapse-magic
The easy way to create a collapsible text block with a 'read-more' label on any page. Also provides a fading text option.
Read More Button – Expand Content Without Refresh
click-to-read-more-button
Easily add a customizable Read More button to expand long posts. Reveal hidden content automatically and smoothly without a page refresh.
Easy Accordion – Responsive Accordion FAQ Builder and Product FAQ
easy-accordion-free
Easily create Accordions, FAQs, and Product FAQ for WooCommerce. Customizable drag & drop WordPress FAQ builder plugin.
Accordion FAQ – Compatible With All Page Builder (Elementor, Gutenberg)
responsive-accordion-and-collapse
Accordion And Collapse is the most easiest drag & drop accordion builder for WordPress. You can add multiple accordion and collapse with this.
Accordions
accordions
Create sleek accordions, tabs, FAQs, and image accordions with a React builder featuring advanced styling, animations, OpenAI support, and customizati …
Read More & Accordion Developer Profile
1 plugin · 10K total installs
How We Detect Read More & Accordion
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/expand-maker/assets/css/accordion.css/wp-content/plugins/expand-maker/assets/js/AccordionBuilder.js/wp-content/plugins/expand-maker/assets/js/YrmLink.js/wp-content/plugins/expand-maker/assets/js/readMore.js/wp-content/plugins/expand-maker/assets/js/readMore_new.js/wp-content/plugins/expand-maker/assets/js/readMore_new_frontend.js/wp-content/plugins/expand-maker/assets/js/readMore_new_admin.js//use.fontawesome.com/releases/v6.2.0/css/all.cssexpand-maker/assets/js/YrmLink.js?ver=expand-maker/assets/js/AccordionBuilder.js?ver=expand-maker/assets/css/accordion.css?ver=HTML / DOM Fingerprints
yrm-accordion-contentaccordion-content-editorbefore-accordion-contentafter-accordion-contentyrm-accordion-item-headeryrm-accordion-item-contentyrm-accordion-itemyrm-accordion-container<!-- create accordian in javascript --><!-- content should be in accordian -->data-yrm-accordion-iddata-yrm-accordion-content-typedata-accordion-iddata-content-typetiny_mcewpYRM_SOUNDS_URL<div class="yrm-accordion-container<div class="before-accordion-content"><div class="after-accordion-content">