
BRTheme FAQ Security & Risk Analysis
wordpress.org/plugins/brtheme-faqA simple FAQ accordion plugin for Elementor or Gutenberg. jQuery-based smooth slide animation. Shortcode: [brtheme_faq]
Is BRTheme FAQ Safe to Use in 2026?
Generally Safe
Score 100/100BRTheme FAQ has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The brtheme-faq plugin v2.1.0 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, file operations, external HTTP requests, and the use of prepared statements for all SQL queries are positive indicators. Furthermore, the high percentage of properly escaped output (88%) suggests a conscious effort to prevent cross-site scripting vulnerabilities. The vulnerability history being clean is also a strong positive sign, indicating the developers have a track record of producing secure code or have promptly addressed any past issues.
However, there are some notable areas of concern. The lack of any nonce checks or capability checks across the entire codebase, particularly with an identified shortcode which represents an entry point, is a significant weakness. While the attack surface is small (one shortcode) and currently lacks direct AJAX or REST API vectors, the absence of authorization checks on the shortcode means any user, regardless of their role or privileges, can potentially interact with its functionality. The taint analysis reporting zero flows is likely due to the limited scope of analysis or the absence of exploitable data flows, but the lack of authorization checks could enable unexpected data injection if the shortcode's functionality were to be expanded or if it interacted with user-supplied data in the future. The zero total taint flows and zero unsanitized paths are good, but the lack of nonces and capability checks is a fundamental security gap that could be exploited if the shortcode handles any dynamic data or actions.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Unescaped output (12% unescaped)
BRTheme FAQ Security Vulnerabilities
BRTheme FAQ Code Analysis
Output Escaping
BRTheme FAQ Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
BRTheme FAQ Maintenance & Trust
Maintenance Signals
Community Trust
BRTheme FAQ Alternatives
FAQ Schema – Accordion, Tab, Slider & Gutenberg Block
faq-schema-ultimate
Create responsive FAQs with accordion, tabs, and slider layouts. Includes FAQ Schema markup, Gutenberg blocks, and Elementor widgets.
FAQly – Ultimate FAQ
faqly-ultimate-faq
FAQly – Ultimate FAQ Plugin: A plugin to manage FAQs and display them as an accordion using a shortcode.
XLTab – Accordions and Tabs for Elementor Page Builder
xl-tab
The XLTab plugin you install after Elementor! and enjoy ultimate tab accordion.
Accordion FAQ with Category
accordion-faq-for-elementor
Responsive FAQ plugin with Accordion and Category for Elementor and page builders. Add FAQ with collapse and toggle activator easily.
Mhshohel Faq
mhshohel-faq
faq in accordian, with custom post, and shortcode.
BRTheme FAQ Developer Profile
2 plugins · 40 total installs
How We Detect BRTheme FAQ
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/brtheme-faq/assets/css/style.css/wp-content/plugins/brtheme-faq/assets/js/faq.js/wp-content/plugins/brtheme-faq/assets/js/faq.jsbrtheme-faq/style.css?ver=brtheme-faq/assets/js/faq.js?ver=HTML / DOM Fingerprints
brfaq-wrapperbrfaq-itembrfaq-questionbrfaq-togglebrfaq-answerdata-index<div class="brfaq-wrapper"><div class="brfaq-item"><button class="brfaq-question"<span class="brfaq-toggle">+