
Create Faq Security & Risk Analysis
wordpress.org/plugins/create-faqWordPressサイトにSEOとAI検索に最適化されたFAQページを簡単に作成・管理できるプラグインです。
Is Create Faq Safe to Use in 2026?
Generally Safe
Score 100/100Create Faq has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'create-faq' plugin v1.0.2 exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, cron events, file operations, external HTTP requests, and dangerous functions is a significant strength. Furthermore, the fact that all SQL queries use prepared statements and the taint analysis shows no critical or high severity flows is highly positive. The plugin also reports no known CVEs, indicating a clean historical security record.
However, there are areas for improvement. The plugin lacks nonce checks and capability checks, which are crucial for securing entry points. While the attack surface is small with only one shortcode, the absence of these checks on it presents a potential risk if the shortcode's functionality is sensitive. The output escaping is not perfect, with 20% of outputs not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if the unescaped content is user-controllable.
In conclusion, the 'create-faq' plugin has many good security practices in place, especially regarding data handling and SQL. The lack of known vulnerabilities is reassuring. Nevertheless, the missing nonce and capability checks, along with the imperfect output escaping, represent the primary security concerns that should be addressed to further harden the plugin.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Improper output escaping (20%)
Create Faq Security Vulnerabilities
Create Faq Code Analysis
Output Escaping
Create Faq Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Create Faq Maintenance & Trust
Maintenance Signals
Community Trust
Create Faq Alternatives
SchemaSense – Smart Structured Data
schemasense-smart-structured-data
Auto-detects FAQ content and generates valid JSON-LD schema for LLMs, GEO (Generative Engine Optimization), and SEO.
FAQ Schema Shortcode
faq-schema-shortcode
Quickly add FAQ sections compatible with structured data to your site using simple shortcodes, improving your SEO.
FAQ Accordion & Schema
faq-accordion-schema
Create FAQ accordions with built-in FAQ schema markup for SEO. Includes shortcode support and styling options.
The SEO Framework – Fast, Automated, Effortless.
autodescription
The fastest feature-complete SEO plugin for professional WordPress websites. Secure, fast, unbranded, and automated SEO. Do less; get better results.
Schema & Structured Data for WP & AMP
schema-and-structured-data-for-wp
Schema & Structured Data adds Google Rich Snippets markup according to Schema.org guidelines to structure your site for SEO.
Create Faq Developer Profile
6 plugins · 70 total installs
How We Detect Create Faq
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/create-faq/assets/css/create-faq.css/wp-content/plugins/create-faq/assets/js/create-faq.js/wp-content/plugins/create-faq/assets/js/create-faq.jscreate-faq/assets/css/create-faq.css?ver=create-faq/assets/js/create-faq.js?ver=HTML / DOM Fingerprints
creafa-faq-wrappercreafa-faq-itemcreafa-faq-questioncreafa-faq-answercreafa-faq-settings<!-- Plugin Name: Create Faq --><!-- Main FAQ class --><!-- FAQ Item --><!-- FAQ Question -->+2 moredata-creafa-accordion-enabledwindow.creafa_settings/wp-json/creafa/v1/faq[creafa_faq]<div class="creafa-faq-wrapper">