XG Accordion Security & Risk Analysis

wordpress.org/plugins/xg-accordion

XG Accordion is a modern Plugin. It's have 05 styles with huge option. You can use this to make easily Accordion on your website easily.

10 active installs v1.0.0 PHP + WP 3.3+ Updated Oct 25, 2018
accordioncollapsefaqwp-accordionwp-faq
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is XG Accordion Safe to Use in 2026?

Generally Safe

Score 85/100

XG Accordion has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "xg-accordion" v1.0.0 plugin presents a mixed security posture. On the positive side, it demonstrates strong output escaping practices and a lack of known vulnerabilities or dangerous functions. There are also no file operations, external HTTP requests, or critical taint analysis findings, which are all positive indicators. However, several concerning areas require attention. The presence of an unprotected AJAX handler significantly expands the attack surface, posing a direct risk of unauthorized actions or information disclosure. The plugin also lacks any nonce or capability checks, further exacerbating the security gap around its entry points. The use of raw SQL queries without prepared statements, even if only one is present, is a potential pathway for SQL injection vulnerabilities. The bundled Select2 library, while common, could pose a risk if it's an outdated version, though this is not explicitly detailed in the provided data. Overall, while the plugin has good underlying code sanitization for output, the lack of authentication and authorization on its entry points, particularly the AJAX handler, is a critical weakness that needs immediate remediation.

Key Concerns

  • Unprotected AJAX handler
  • Missing nonce checks on AJAX
  • Missing capability checks
  • Raw SQL without prepared statements
Vulnerabilities
None known

XG Accordion Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

XG Accordion Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
27
632 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

0% prepared1 total queries

Output Escaping

96% escaped659 total outputs
Attack Surface
1 unprotected

XG Accordion Attack Surface

Entry Points3
Unprotected1

AJAX Handlers 1

authwp_ajax_xga_accordion_sortingadmin\xg_accrodion_menu_page.php:12

Shortcodes 2

[xga__accordion] public\shortcode\class-xga-accordion-shortcode.php:14
[xgp_accordion_shortcode] public\wpbakery\class-xga-wpb-accordion-widget.php:18
WordPress Hooks 9
actioninitadmin\xg_accrodion_custom_post_type.php:5
actionadmin_enqueue_scriptsadmin\xg_accrodion_menu_page.php:11
actionpre_get_postsadmin\xg_accrodion_menu_page.php:13
actioninitpublic\wpbakery\class-xga-wpb-accordion-widget.php:17
actionvc_before_initpublic\xga-helpers.php:12
actionelementor/initpublic\xga-helpers.php:17
actionelementor/widgets/widgets_registeredpublic\xga-helpers.php:30
actionplugins_loadedxg_accordion_init.php:32
actionwp_enqueue_scriptsxg_accordion_init.php:33
Maintenance & Trust

XG Accordion Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedOct 25, 2018
PHP min version
Downloads15K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

XG Accordion Developer Profile

xgenious

3 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect XG Accordion

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/xg-accordion/assets/css/font-awesome.css/wp-content/plugins/xg-accordion/assets/css/accordion.css/wp-content/plugins/xg-accordion/assets/js/xga.accrodion.js/wp-content/plugins/xg-accordion/admin/assets/css/xga-admin.css/wp-content/plugins/xg-accordion/admin/assets/js/xga-admin.js
Script Paths
/wp-content/plugins/xg-accordion/assets/js/xga.accrodion.js/wp-content/plugins/xg-accordion/admin/assets/js/xga-admin.js
Version Parameters
xg-accordion/assets/css/accordion.css?ver=xga-accordion/assets/js/xga.accrodion.js?ver=

HTML / DOM Fingerprints

CSS Classes
xga-accordion-wrapper-xga-accrodion-
Data Attributes
data-parent
Shortcode Output
[xga__accordion
FAQ

Frequently Asked Questions about XG Accordion