WPB Accordion Menu – Collapsible Vertical Sidebar Menu – WooCommerce Category Accordion Security & Risk Analysis

wordpress.org/plugins/wpb-accordion-menu-or-category

WPB Accordion Menu is a collapsible vertical sidebar menu for WordPress. It can display WooCommerce product categories and the menu accordion.

10K active installs v1.8.4 PHP + WP 5.0+ Updated Mar 13, 2026
accordion-menumenusidebar-menuvertical-menuwoocommerce-menu
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPB Accordion Menu – Collapsible Vertical Sidebar Menu – WooCommerce Category Accordion Safe to Use in 2026?

Generally Safe

Score 100/100

WPB Accordion Menu – Collapsible Vertical Sidebar Menu – WooCommerce Category Accordion has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 21d ago
Risk Assessment

The "wpb-accordion-menu-or-category" plugin version 1.8.4 exhibits a generally strong security posture, primarily due to its diligent use of prepared statements for SQL queries and a high percentage of properly escaped output. The absence of known CVEs and a history of no recorded vulnerabilities further bolster this positive assessment, suggesting a commitment to secure coding practices by the developers. The plugin also demonstrates good awareness by implementing nonce checks on all identified AJAX handlers, preventing common cross-site request forgery attacks.

However, a notable concern arises from the taint analysis, which identified two flows with unsanitized paths. While these flows did not reach critical or high severity levels in the static analysis, the presence of unsanitized paths indicates a potential for attackers to manipulate input that could lead to unexpected or harmful behavior, especially if combined with other, less secure components. The lack of capability checks on any entry points, including AJAX handlers and shortcodes, also presents a weakness. This means that any authenticated user, regardless of their role or permissions, could potentially trigger these functionalities, which could be exploited if vulnerabilities exist within those functions.

In conclusion, while the plugin has commendable security fundamentals like prepared statements and output escaping, the identified unsanitized paths and the absence of capability checks are areas that warrant attention and mitigation. The vulnerability history is excellent, but the static analysis does reveal specific technical risks that should be addressed to further solidify its security.

Key Concerns

  • Unsanitized paths in taint analysis
  • No capability checks on entry points
Vulnerabilities
None known

WPB Accordion Menu – Collapsible Vertical Sidebar Menu – WooCommerce Category Accordion Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WPB Accordion Menu – Collapsible Vertical Sidebar Menu – WooCommerce Category Accordion Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
21
309 escaped
Nonce Checks
8
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped330 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
edit_shortcode_page_content (admin\class.admin-page.php:582)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WPB Accordion Menu – Collapsible Vertical Sidebar Menu – WooCommerce Category Accordion Attack Surface

Entry Points8
Unprotected0

AJAX Handlers 5

authwp_ajax_wpb-fire-shortcode-popupadmin\class.admin-page.php:39
authwp_ajax_wpb-fire-duplicate-shortcodeadmin\class.admin-page.php:40
authwp_ajax_wpb-fire-delete-shortcodeadmin\class.admin-page.php:41
authwp_ajax_wpb-fire-add-shortcodeadmin\class.admin-page.php:42
authwp_ajax_wpb_am_fire_save_shortcodeadmin\class.admin-page.php:43

Shortcodes 3

[wpb_wmca_accordion_pro] frontend\shortcode.php:16
[wpb_category_accordion] inc\wpb-wmca-shortcodes.php:66
[wpb_menu_accordion] inc\wpb-wmca-shortcodes.php:116
WordPress Hooks 22
actioninitadmin\class.admin-page.php:31
actionadmin_menuadmin\class.admin-page.php:36
actionadmin_enqueue_scriptsadmin\class.admin-page.php:37
filteradmin_footer_textadmin\class.admin-page.php:45
filterallowed_redirect_hostsadmin\class.admin-page.php:439
filterallowed_redirect_hostsadmin\class.admin-page.php:453
actionadmin_noticesadmin\class.discount-notice.php:16
actionadmin_initadmin\class.discount-notice.php:17
actioninitadmin\shortcodebuilder\class.shortcode-cpt.php:23
actionelementor/frontend/after_register_scriptselementor\wpb-wmca-elementor.php:108
actionelementor/frontend/after_register_styleselementor\wpb-wmca-elementor.php:109
actionelementor/widgets/registerelementor\wpb-wmca-elementor.php:110
actioninitinc\blocks\accordion.php:111
actionelementor/initinc\elementor\elementor.php:71
actionelementor/widgets/registerinc\elementor\elementor.php:111
actionelementor/frontend/after_register_scriptsinc\elementor\elementor.php:112
actionelementor/frontend/after_register_stylesinc\elementor\elementor.php:113
filterwpb_wcma_wp_list_categories_argsinc\helper\class.woocommerce.php:14
actionwidgets_initinc\widgets\class.widgets-register.php:16
actionplugins_loadedmain.php:69
actionwp_enqueue_scriptsmain.php:99
actionafter_setup_thememain.php:101
Maintenance & Trust

WPB Accordion Menu – Collapsible Vertical Sidebar Menu – WooCommerce Category Accordion Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 13, 2026
PHP min version
Downloads176K

Community Trust

Rating86/100
Number of ratings51
Active installs10K
Developer Profile

WPB Accordion Menu – Collapsible Vertical Sidebar Menu – WooCommerce Category Accordion Developer Profile

WPBean

25 plugins · 40K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
20 days
View full developer profile
Detection Fingerprints

How We Detect WPB Accordion Menu – Collapsible Vertical Sidebar Menu – WooCommerce Category Accordion

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpb-accordion-menu-or-category/assets/js/jquery.cookie.js/wp-content/plugins/wpb-accordion-menu-or-category/assets/js/jquery.navgoco.min.js/wp-content/plugins/wpb-accordion-menu-or-category/assets/js/accordion-init.js/wp-content/plugins/wpb-accordion-menu-or-category/assets/css/wpb_wmca_style.css
Script Paths
/wp-content/plugins/wpb-accordion-menu-or-category/assets/js/jquery.cookie.js/wp-content/plugins/wpb-accordion-menu-or-category/assets/js/jquery.navgoco.min.js/wp-content/plugins/wpb-accordion-menu-or-category/assets/js/accordion-init.js
Version Parameters
wpb-accordion-menu-or-category/assets/js/jquery.cookie.js?ver=wpb-accordion-menu-or-category/assets/js/jquery.navgoco.min.js?ver=wpb-accordion-menu-or-category/assets/js/accordion-init.js?ver=wpb-accordion-menu-or-category/assets/css/wpb_wmca_style.css?ver=

HTML / DOM Fingerprints

CSS Classes
wpb-wmca-accordion-menuwpb-wmca-activewpb-wmca-parentwpb-wmca-childwpb_wmca_shortcode_builder
Data Attributes
data-wpb-wmca-shortcode-id
JS Globals
wpb_wmca_ajax_objectWPB_Accordion_Menu_ShortCodeWPBean_Accordion_Menu_Admin_Page
REST Endpoints
/wp-json/wpb-wmca/v1/shortcodes
Shortcode Output
[wpb_wmca_accordion][wpb_wmca_accordion_pro]
FAQ

Frequently Asked Questions about WPB Accordion Menu – Collapsible Vertical Sidebar Menu – WooCommerce Category Accordion