DmiMag FAQs Security & Risk Analysis

wordpress.org/plugins/dmimag-faqs

DmiMag FAQs - is a lightweight WordPress FAQ Plugin

10 active installs v1.2.7 PHP 7.4+ WP 6.0+ Updated Dec 11, 2025
faqfaq-pluginfaqsguidewordpress-faq
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is DmiMag FAQs Safe to Use in 2026?

Generally Safe

Score 100/100

DmiMag FAQs has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "dmimag-faqs" plugin v1.2.7 exhibits a generally good security posture with several strong indicators. The absence of any known CVEs and the consistent use of prepared statements for SQL queries are significant strengths. Furthermore, the high percentage of properly escaped output and the presence of nonce and capability checks demonstrate adherence to common WordPress security best practices. This indicates a developer who is mindful of security in their coding.

However, there is one notable concern identified in the static analysis: one AJAX handler lacks authentication checks. This creates a potential attack vector where an unauthenticated user could interact with a plugin function, which could lead to unintended consequences depending on what the AJAX handler performs. While taint analysis shows no critical or high severity issues and the attack surface is small, this single unprotected entry point warrants attention.

Overall, the plugin's history of no vulnerabilities is a positive sign, suggesting a mature and secure codebase. The main weakness lies in the unprotected AJAX handler. Addressing this would significantly improve the plugin's security.

Key Concerns

  • AJAX handler without auth checks
Vulnerabilities
None known

DmiMag FAQs Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

DmiMag FAQs Release Timeline

v1.2.7Current
v1.2.6
v1.2.5
v1.2.4
v1.2.3
Code Analysis
Analyzed Mar 16, 2026

DmiMag FAQs Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
32 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped34 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
dmimag_faqs_render_postbox_html (includes\class-dmimag-faqs-postbox.php:123)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

DmiMag FAQs Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 1

authwp_ajax_dmimag_faqs_add_postboxincludes\class-dmimag-faqs.php:197

Shortcodes 1

[dmimag-faqs] includes\class-dmimag-faqs.php:289
WordPress Hooks 13
actionplugins_loadedincludes\class-dmimag-faqs.php:159
actioninitincludes\class-dmimag-faqs.php:180
actionadd_meta_boxesincludes\class-dmimag-faqs.php:205
actionadmin_menuincludes\class-dmimag-faqs.php:213
actionedit_form_after_titleincludes\class-dmimag-faqs.php:221
actionedit_form_advancedincludes\class-dmimag-faqs.php:229
actionwp_insert_post_dataincludes\class-dmimag-faqs.php:237
actionadmin_enqueue_scriptsincludes\class-dmimag-faqs.php:258
actionadmin_enqueue_scriptsincludes\class-dmimag-faqs.php:260
actionadmin_enqueue_scriptsincludes\class-dmimag-faqs.php:262
actionadmin_print_footer_scriptsincludes\class-dmimag-faqs.php:264
actionwp_enqueue_scriptsincludes\class-dmimag-faqs.php:279
actionwp_enqueue_scriptsincludes\class-dmimag-faqs.php:281
Maintenance & Trust

DmiMag FAQs Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 11, 2025
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

DmiMag FAQs Developer Profile

dmimag

2 plugins · 30 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DmiMag FAQs

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dmimag-faqs/css/dmimag-faqs-admin.css/wp-content/plugins/dmimag-faqs/js/dmimag-faqs-admin.js
Script Paths
/wp-content/plugins/dmimag-faqs/js/dmimag-faqs-admin.js
Version Parameters
dmimag-faqs-admin.css?ver=dmimag-faqs-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
dmimag-faqs-shortcodedmimag-faqs-copy-to-clipboard
Data Attributes
data-faqdata-type
Shortcode Output
[dmimag-faqs faq= type=accordion] type=guide]
FAQ

Frequently Asked Questions about DmiMag FAQs