
Lightweight Accordion Security & Risk Analysis
wordpress.org/plugins/lightweight-accordionSimple accordion for adding collapse elements to pages without affecting page load time. Includes Gutenberg block and shortcode for classic editor.
Is Lightweight Accordion Safe to Use in 2026?
Generally Safe
Score 96/100Lightweight Accordion has a strong security track record. Known vulnerabilities have been patched promptly.
The 'lightweight-accordion' plugin version 1.6.0 exhibits a mixed security posture. While the static analysis indicates good practices such as 100% prepared statement usage for SQL queries and a high percentage (91%) of properly escaped output, significant concerns remain. The absence of nonce checks and capability checks on any entry points, despite having two shortcodes, represents a notable weakness. The plugin's history is particularly alarming, with a total of three known medium-severity CVEs, all of which are related to Cross-Site Scripting (XSS). The fact that all historical vulnerabilities are now patched is a positive sign, but the recurring nature of XSS vulnerabilities suggests potential systemic issues in input sanitization or output rendering that may not have been fully addressed across all versions. Despite the lack of critical or high severity issues in the current static analysis, the historical pattern of XSS and the missing authorization checks on shortcodes warrant careful consideration and ongoing monitoring.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
- History of 3 medium XSS vulnerabilities
Lightweight Accordion Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Lightweight Accordion <= 1.5.20 - Authenticated (Contributor+) Stored Cross-Site Scripting
Lightweight Accordion <= 1.5.16 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode
Lightweight Accordion <= 1.5.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Lightweight Accordion Code Analysis
Output Escaping
Lightweight Accordion Attack Surface
Shortcodes 2
WordPress Hooks 4
Maintenance & Trust
Lightweight Accordion Maintenance & Trust
Maintenance Signals
Community Trust
Lightweight Accordion Alternatives
SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels)
slingblocks
A minimalist Gutenberg Block Plugin that extends Gutenberg to provide page building capabilities.
Accordion Toggle
accordion-toggle
Display Your FAQs & Improve User Experience with Accordion/Toggle block.
Toggles
toggles
An easy way to hide and reveal content.
AinoBlocks Accordion Faq Block
aino-accordion-faq-block
Create Frequently Asked Question's and Accordions with Aino's Accordion and FAQ Block.
Hot Blocks
hot-blocks
A collection of several blocks for new WordPress editor (Gutenberg).
Lightweight Accordion Developer Profile
5 plugins · 15K total installs
How We Detect Lightweight Accordion
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lightweight-accordion/css/min/lightweight-accordion.min.css/wp-content/plugins/lightweight-accordion/css/min/editor-styles.min.csslightweight-accordion/css/min/lightweight-accordion.min.css?ver=lightweight-accordion/css/min/editor-styles.min.css?ver=HTML / DOM Fingerprints
lightweight-accordionborderedlightweight-accordion-titlelightweight-accordion-bodyhas-text-colorhas-backgrounddata-context="lightweight-accordion/groupName"idopenname itemscope itemprop="mainEntity"+6 more<div class="lightweight-accordion<details<summary class="lightweight-accordion-title"<div class="lightweight-accordion-body"