AD Sliding FAQ Security & Risk Analysis

wordpress.org/plugins/ad-sliding-faq

Create a nice and accessible accordion FAQ section with sliding Q/A.

30 active installs v2.5 PHP + WP 4.0+ Updated Apr 14, 2026
faqfaq-pluginfaqsfrequently-asked-questionswordpress-faq
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEJan 6, 2026
Download
Safety Verdict

Is AD Sliding FAQ Safe to Use in 2026?

Mostly Safe

Score 78/100

AD Sliding FAQ is generally safe to use. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Jan 6, 2026Updated 1mo ago
Risk Assessment

The 'ad-sliding-faq' plugin v2.5 exhibits a mixed security posture. While it demonstrates good practices by avoiding dangerous functions, raw SQL queries, file operations, and external HTTP requests, several critical areas raise significant concerns. The complete absence of nonce checks and capability checks across all identified entry points, combined with a concerningly low output escaping rate (33%), suggests a high susceptibility to various attacks. The static analysis also indicates zero taint flows were analyzed, which is unusual and might imply incomplete analysis or a lack of complex data handling, but it doesn't negate the other identified weaknesses.

The plugin's vulnerability history is a major red flag, with one known medium-severity CVE that remains unpatched. The fact that this CVE is a Cross-Site Scripting (XSS) vulnerability, coupled with the low output escaping rate observed in the static analysis, strongly suggests that XSS is a recurring and potentially exploitable issue. The presence of a recent vulnerability (2026-01-06) indicates ongoing security challenges with this plugin.

In conclusion, despite some positive security implementations, the 'ad-sliding-faq' plugin v2.5 has critical weaknesses. The lack of robust authorization and input validation mechanisms, combined with a history of unpatched XSS vulnerabilities and poor output sanitization, presents a significant security risk. Users should exercise extreme caution and prioritize updating or finding an alternative plugin.

Key Concerns

  • Unpatched CVE
  • Missing nonce checks
  • Missing capability checks
  • Low output escaping (33%)
Vulnerabilities
1 published

AD Sliding FAQ Security Vulnerabilities

CVEs by Year

1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-14122medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

AD Sliding FAQ <= 2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

Jan 6, 2026Unpatched
Version History

AD Sliding FAQ Release Timeline

v2.5Current1 CVE
v2.41 CVE
v2.31 CVE
v2.21 CVE
v2.11 CVE
v2.01 CVE
v1.9.11 CVE
v1.91 CVE
v1.81 CVE
v1.71 CVE
v1.6.61 CVE
v1.6.51 CVE
Code Analysis
Analyzed Apr 16, 2026

AD Sliding FAQ Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

33% escaped6 total outputs
Attack Surface

AD Sliding FAQ Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[sliding_faq] any-sliding-faq.php:294
WordPress Hooks 8
actioninitany-sliding-faq-cpt.php:67
actioninitany-sliding-faq-cpt.php:101
filtermanage_edit-faq-item_columnsany-sliding-faq-cpt.php:127
filtermanage_faq-item_posts_custom_columnany-sliding-faq-cpt.php:128
filterenter_title_hereany-sliding-faq-cpt.php:142
actionwp_enqueue_scriptsany-sliding-faq.php:92
actionwp_enqueue_scriptsany-sliding-faq.php:112
actionadmin_initany-sliding-faq.php:327
Maintenance & Trust

AD Sliding FAQ Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 14, 2026
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs30
Developer Profile

AD Sliding FAQ Developer Profile

Thomas Villain

1 plugin · 30 total installs

79
trust score
Avg Security Score
78/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AD Sliding FAQ

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ad-sliding-faq/js/sliding-faq.js/wp-content/plugins/ad-sliding-faq/css/sliding-faq.css
Script Paths
/wp-content/plugins/ad-sliding-faq/js/sliding-faq.js
Version Parameters
ad-sliding-faq/js/sliding-faq.js?ver=ad-sliding-faq/css/sliding-faq.css?ver=

HTML / DOM Fingerprints

CSS Classes
faq-listfaq-list--itemfaq-list--questionfaq-list--titlefaq-list--answer
Data Attributes
aria-controlsaria-expandedaria-hidden
Shortcode Output
[sliding_faq]
FAQ

Frequently Asked Questions about AD Sliding FAQ