
Subpage as Expandable Text Shortcode Security & Risk Analysis
wordpress.org/plugins/subpages-expandAdd [subpages_expand] to any parent page. All child pages' titles are shown as links that expand to content when clicked
Is Subpage as Expandable Text Shortcode Safe to Use in 2026?
Generally Safe
Score 92/100Subpage as Expandable Text Shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "subpages-expand" v1.20 plugin demonstrates a strong security posture based on the provided static analysis. There are no identified dangerous functions, file operations, or external HTTP requests. The plugin also shows excellent practices regarding SQL queries, with 100% using prepared statements, and all output is properly escaped. The absence of critical or high severity taint flows further reinforces this positive assessment. The plugin's vulnerability history is clean, with no recorded CVEs, suggesting a history of secure development or diligent patching if issues arose previously. The limited attack surface, consisting of a single shortcode, is also a positive factor. However, a notable concern is the complete lack of nonce and capability checks across all entry points. While the current data indicates no unprotected entry points, relying solely on other security mechanisms without these WordPress-specific checks represents a potential weakness that could be exploited if other layers of defense are bypassed or if the plugin evolves with new features. This absence of built-in WordPress security primitives is the primary area of concern in an otherwise well-developed plugin.
Key Concerns
- Missing nonce checks on entry points
- Missing capability checks on entry points
Subpage as Expandable Text Shortcode Security Vulnerabilities
Subpage as Expandable Text Shortcode Code Analysis
Subpage as Expandable Text Shortcode Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Subpage as Expandable Text Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
Subpage as Expandable Text Shortcode Alternatives
Cool Text Effect
cool-text-effect
This plugin will enable text effect in your wordpress theme. You can embed cool textEffect via shortcode in everywhere you want, even in theme files.
Perfect Accordion
perfect-accordion
This is a accordion plugin to extend your website's beauty and make it gorgeous. By activating this plugin user can get a custom post in Dashboar …
WP-PageNavi
wp-pagenavi
Adds a more advanced paging navigation interface.
Exclude Pages
exclude-pages
This plugin adds a checkbox, “include this page in menus”, uncheck this to exclude pages from the page navigation that users see on your site.
CC Child Pages
cc-child-pages
Display WordPress child pages in a responsive grid or list using a shortcode, Gutenberg block or Elementor widget.
Subpage as Expandable Text Shortcode Developer Profile
2 plugins · 3K total installs
How We Detect Subpage as Expandable Text Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/subpages-expand/js/add_button_editor.js.php/wp-content/plugins/subpages-expand/js/add_button_editor.js.phpsubpages-expand/style.css?ver=HTML / DOM Fingerprints
subpage_titlesubpage_contenttexts<h2 class='subpage_title' style='cursor:pointer'><div class='subpage_content' style='display:none'>