Show-Hide / Collapse-Expand Security & Risk Analysis

wordpress.org/plugins/show-hidecollapse-expand

Save space on your pages, posts, sidebars. Hide the content before user clicks to see it. Collapse long lists, create FAQs & more.

10K active installs v1.3.0 PHP + WP 4.2+ Updated Mar 19, 2023
collapseexpandfaqhide-contentshow-content
84
B · Generally Safe
CVEs total2
Unpatched0
Last CVEJan 4, 2023
Safety Verdict

Is Show-Hide / Collapse-Expand Safe to Use in 2026?

Mostly Safe

Score 84/100

Show-Hide / Collapse-Expand is generally safe to use though it hasn't been updated recently. 2 past CVEs were resolved. Keep it updated.

2 known CVEsLast CVE: Jan 4, 2023Updated 3yr ago
Risk Assessment

The "show-hidecollapse-expand" plugin version 1.3.0 exhibits a mixed security posture. The static analysis reveals a very small attack surface with no apparent unprotected entry points, and a strong adherence to secure coding practices such as using prepared statements for all SQL queries and a high percentage of properly escaped output. The absence of dangerous functions and external HTTP requests is also positive. However, the plugin's vulnerability history is a significant concern, with two documented medium severity vulnerabilities: Cross-site Scripting and Missing Authorization. The fact that both of these are listed as 'currently unpatched' according to the data provided, despite the last vulnerability being in early 2023, suggests a potential for ongoing security weaknesses if these issues are not actively addressed by the developer. While the current version might be clean of critical issues based on the taint analysis, the historical pattern indicates a need for caution and vigilance regarding past vulnerability types.

Key Concerns

  • Medium severity CVEs present in history
  • Missing authorization vulnerability in history
  • Cross-site Scripting vulnerability in history
Vulnerabilities
2

Show-Hide / Collapse-Expand Security Vulnerabilities

CVEs by Year

2 CVEs in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2022-4829medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Show-Hide / Collapse-Expand <= 1.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Jan 4, 2023 Patched in 1.3.0 (384d)

Show-Hide / Collapse-Expand <= 1.2.6 - Missing Authorization

Jan 4, 2023 Patched in 1.3.0 (384d)
Code Analysis
Analyzed Mar 16, 2026

Show-Hide / Collapse-Expand Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
29 escaped
Nonce Checks
1
Capability Checks
0
File Operations
4
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

97% escaped30 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
bg_show_hide_save_plugin_settings (bg_show_hide.php:126)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Show-Hide / Collapse-Expand Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filterthe_contentbg_show_hide.php:71
filterplugin_action_linksbg_show_hide.php:332
Maintenance & Trust

Show-Hide / Collapse-Expand Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedMar 19, 2023
PHP min version
Downloads158K

Community Trust

Rating92/100
Number of ratings20
Active installs10K
Developer Profile

Show-Hide / Collapse-Expand Developer Profile

buntegiraffe

2 plugins · 10K total installs

69
trust score
Avg Security Score
85/100
Avg Patch Time
384 days
View full developer profile
Detection Fingerprints

How We Detect Show-Hide / Collapse-Expand

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/show-hidecollapse-expand/assets/css/bg-show-hide.css/wp-content/plugins/show-hidecollapse-expand/assets/js/bg-show-hide-mce-plugin.js
Script Paths
/wp-content/plugins/show-hidecollapse-expand/assets/js/bg-show-hide-mce-plugin.js

HTML / DOM Fingerprints

CSS Classes
bg-showmore-plg-linkbg-margibg-hidden-content
HTML Comments
<!-- TODO: write to log -->
Data Attributes
bg_collapse_expandbg-show-more-text-bg-show-less-text-bg-showmore-action-
Shortcode Output
<a id='bg-showmore-action-<div class="bg-margi<input type='hidden' bg_collapse_expand='
FAQ

Frequently Asked Questions about Show-Hide / Collapse-Expand