
Master Paper Collapse Toggle Security & Risk Analysis
wordpress.org/plugins/master-paper-collapse-toggleAllows you to create toggles in format of collapsible paper cards, inspired by Google Material Design.
Is Master Paper Collapse Toggle Safe to Use in 2026?
Use With Caution
Score 63/100Master Paper Collapse Toggle has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The plugin 'master-paper-collapse-toggle' v1.1 exhibits a mixed security posture. While the static analysis reveals good practices such as 100% prepared statements for SQL queries, proper output escaping, and no identified dangerous functions or file operations, there are significant concerns that detract from its overall security. The absence of any capability checks or nonce checks across all identified entry points, including the single shortcode, is a critical oversight. This means that any user, regardless of their role, could potentially interact with or trigger functionality within this shortcode, which could be exploited if the shortcode's logic has an inherent vulnerability.
The vulnerability history is particularly concerning, with one known medium severity CVE for Cross-Site Scripting that remains unpatched. The fact that this vulnerability was recently discovered and is still present in version 1.1 indicates a lack of prompt security patching within the development cycle. This pattern suggests a potential for recurring vulnerabilities if the development process doesn't prioritize security updates. The absence of any taint analysis results is unusual and could imply that the analysis tool had limited scope or that the code structure did not present obvious taint flows, but it does not negate the risks identified through other means.
In conclusion, while the code base shows some commendable security practices in areas like SQL and output handling, the lack of robust authentication and authorization checks on its entry points, coupled with a recently discovered and unpatched medium-severity XSS vulnerability, presents a notable risk. The plugin's strengths are overshadowed by these critical weaknesses, suggesting a need for immediate attention to patch the existing CVE and implement proper authorization mechanisms.
Key Concerns
- Unpatched CVE
- Missing capability checks on entry points
- Missing nonce checks on entry points
Master Paper Collapse Toggle Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Master Paper Collapse Toggle <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Master Paper Collapse Toggle Code Analysis
Master Paper Collapse Toggle Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Master Paper Collapse Toggle Maintenance & Trust
Maintenance Signals
Community Trust
Master Paper Collapse Toggle Alternatives
Accord Blocks – The Easiest Accordion & FAQ Blocks
accord-blocks
Create beautiful and SEO-friendly accordions and FAQs with Gutenberg blocks. Build engaging content sections and knowledge bases easily.
Show Hide Accordion by MediaArt
show-hide-accordion-by-mediaart
Create collapse/expand sections and accordions via shortcodes (ma_collapse + legacy bg_collapse).
Accordion FAQ – Compatible With All Page Builder (Elementor, Gutenberg)
responsive-accordion-and-collapse
Accordion And Collapse is the most easiest drag & drop accordion builder for WordPress. You can add multiple accordion and collapse with this.
Read More & Accordion
expand-maker
Easily hide or reveal long content with Read More buttons, accordions, and popups. Streamline your WordPress site's layout while enhancing user e …
Meks Flexible Shortcodes
meks-flexible-shortcodes
Add some cool elements to your post/page content with flexible shortcodes.
Master Paper Collapse Toggle Developer Profile
11 plugins · 1K total installs
How We Detect Master Paper Collapse Toggle
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/master-paper-collapse-toggle/js/master-paper-collapse.min.js/wp-content/plugins/master-paper-collapse-toggle/css/master-paper-collapse.min.cssjs/master-paper-collapse.min.jsmaster-paper-collapse.min.css?ver=master-paper-collapse.min.js?ver=HTML / DOM Fingerprints
collapse-cardmpc-titlempc-iconmpc-body<div class="collapse-card"><div class="mpc-title"<i class="mpc-icon fa fa-2x fa-fw"></i></strong> </div><div class="mpc-body">