
AD Sliding FAQ Security & Risk Analysis
wordpress.org/plugins/ad-sliding-faqCreate a nice and accessible accordion FAQ section with sliding Q/A.
Is AD Sliding FAQ Safe to Use in 2026?
Mostly Safe
Score 78/100AD Sliding FAQ is generally safe to use. 1 past CVE were resolved.
The 'ad-sliding-faq' plugin v2.5 exhibits a mixed security posture. While it demonstrates good practices by avoiding dangerous functions, raw SQL queries, file operations, and external HTTP requests, several critical areas raise significant concerns. The complete absence of nonce checks and capability checks across all identified entry points, combined with a concerningly low output escaping rate (33%), suggests a high susceptibility to various attacks. The static analysis also indicates zero taint flows were analyzed, which is unusual and might imply incomplete analysis or a lack of complex data handling, but it doesn't negate the other identified weaknesses.
The plugin's vulnerability history is a major red flag, with one known medium-severity CVE that remains unpatched. The fact that this CVE is a Cross-Site Scripting (XSS) vulnerability, coupled with the low output escaping rate observed in the static analysis, strongly suggests that XSS is a recurring and potentially exploitable issue. The presence of a recent vulnerability (2026-01-06) indicates ongoing security challenges with this plugin.
In conclusion, despite some positive security implementations, the 'ad-sliding-faq' plugin v2.5 has critical weaknesses. The lack of robust authorization and input validation mechanisms, combined with a history of unpatched XSS vulnerabilities and poor output sanitization, presents a significant security risk. Users should exercise extreme caution and prioritize updating or finding an alternative plugin.
Key Concerns
- Unpatched CVE
- Missing nonce checks
- Missing capability checks
- Low output escaping (33%)
AD Sliding FAQ Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
AD Sliding FAQ <= 2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
AD Sliding FAQ Release Timeline
AD Sliding FAQ Code Analysis
Output Escaping
AD Sliding FAQ Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
AD Sliding FAQ Maintenance & Trust
Maintenance Signals
Community Trust
AD Sliding FAQ Alternatives
Mos FAQs
mos-faqs
Mos FAQs plugin that lets you easily create, order and publicize FAQs using shortcodes.
DmiMag FAQs
dmimag-faqs
DmiMag FAQs - is a lightweight WordPress FAQ Plugin
MYFAQ Plugin
myfaq
A simple and beauty WordPress FAQ Plugin : ) , please use [my_faq] shortcode!
Advanced FAQ Manager
advanced-faq-manager
The FAQ Manager plugin lets you create & manage FAQs in an accordion style. Use this WordPress FAQ plugin to group and display FAQs with ease.
FAQ Concertina
faq-concertina
Display FAQs in an expandable concertina or accordion section. FAQs can be ordered and categorised, and their appearance can be customised.
AD Sliding FAQ Developer Profile
1 plugin · 30 total installs
How We Detect AD Sliding FAQ
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ad-sliding-faq/js/sliding-faq.js/wp-content/plugins/ad-sliding-faq/css/sliding-faq.css/wp-content/plugins/ad-sliding-faq/js/sliding-faq.jsad-sliding-faq/js/sliding-faq.js?ver=ad-sliding-faq/css/sliding-faq.css?ver=HTML / DOM Fingerprints
faq-listfaq-list--itemfaq-list--questionfaq-list--titlefaq-list--answeraria-controlsaria-expandedaria-hidden[sliding_faq]