LZ Accordion Security & Risk Analysis

wordpress.org/plugins/lz-accordion

This plugin will add an expand collapse accordion feature inside a post or page.

0 active installs v1.0 PHP + WP 4.0+ Updated Unknown
accordionjquery-accordion
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LZ Accordion Safe to Use in 2026?

Generally Safe

Score 100/100

LZ Accordion has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "lz-accordion" plugin version 1.0 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL queries, file operations, and external HTTP requests is commendable. Furthermore, the complete absence of reported CVEs in its vulnerability history suggests a consistent track record of security diligence, or potentially limited exposure. The code analysis also indicates that all identified SQL queries utilize prepared statements and all output is properly escaped, which are excellent security practices. The limited attack surface, consisting solely of shortcodes, and the lack of unprotected entry points further bolster its security profile.

However, the analysis does highlight a significant area for concern: the complete absence of nonce checks and capability checks across all identified entry points. While the current version may not have exploitable vulnerabilities due to other security measures or a small attack surface, this lack of explicit authorization and validation creates a potential weakness. Should a future version introduce functionality that handles sensitive data or performs critical actions, the absence of these checks could become a critical security flaw, opening the door to unauthorized access or manipulation. Therefore, while the plugin's current state is relatively secure, the omission of nonce and capability checks represents a notable risk that should be addressed.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

LZ Accordion Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

LZ Accordion Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

LZ Accordion Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[lzaccordion] main.php:60
[lztoggle] main.php:69
WordPress Hooks 4
actioninitmain.php:20
filtermce_external_pluginsmain.php:38
filtermce_buttonsmain.php:39
actioninitmain.php:51
Maintenance & Trust

LZ Accordion Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedUnknown
PHP min version
Downloads951

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

LZ Accordion Developer Profile

Nazmul Islam

3 plugins · 10 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect LZ Accordion

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lz-accordion/js/main.js/wp-content/plugins/lz-accordion/js/active.js/wp-content/plugins/lz-accordion/css/style.css/wp-content/plugins/lz-accordion/js/accordian-button.js
Script Paths
/wp-content/plugins/lz-accordion/js/main.js/wp-content/plugins/lz-accordion/js/active.js
Version Parameters
/wp-content/plugins/lz-accordion/js/active.js?ver=1.0

HTML / DOM Fingerprints

CSS Classes
tab_content
Shortcode Output
<div id="lz-tabs"><h3></h3><div>
FAQ

Frequently Asked Questions about LZ Accordion