Accordion FAQ Security & Risk Analysis

wordpress.org/plugins/elfsight-faq

Anticipate your clients’ questions and eliminate doubts with informative FAQ.

40 active installs v1.0.1 PHP + WP 5.0+ Updated Sep 19, 2025
accordion-faqfaqfaq-pluginresponsive-faqwordpress-faq
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Accordion FAQ Safe to Use in 2026?

Generally Safe

Score 100/100

Accordion FAQ has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The elfsight-faq plugin v1.0.1 exhibits a generally strong security posture with no recorded vulnerabilities or critical findings in taint analysis. The absence of any known CVEs, critical or high severity taint flows, and a minimal attack surface are positive indicators. However, the static analysis reveals areas for improvement. The low percentage of properly escaped output (24%) suggests a significant risk of cross-site scripting (XSS) vulnerabilities. The presence of unsanitized path flows in the taint analysis, even if not reaching critical severity in this run, indicates potential for path traversal or file inclusion vulnerabilities if not handled carefully by other security measures. The lack of capability checks on entry points is also a concern, as it means any interaction with these entry points might not be properly authorized for privileged actions.

While the plugin benefits from a clean vulnerability history, the static analysis highlights concerning code quality in output escaping. The taint analysis, despite no critical findings, does point to potential weaknesses in how data is handled. The minimal attack surface and use of prepared statements in SQL queries are strengths. Overall, the plugin is in a relatively good state, but the output escaping and taint analysis findings warrant attention to prevent future security issues.

Key Concerns

  • Low percentage of properly escaped output
  • Taint flows with unsanitized paths
  • No capability checks on entry points
Vulnerabilities
None known

Accordion FAQ Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Accordion FAQ Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
2 prepared
Unescaped Output
19
6 escaped
Nonce Checks
1
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

67% prepared3 total queries

Output Escaping

24% escaped25 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
getList (core\includes\widgets-api.php:92)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Accordion FAQ Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionwp_footercore\elfsight-plugin.php:39
actionadmin_menucore\includes\admin.php:61
actionadmin_initcore\includes\admin.php:62
actionadmin_enqueue_scriptscore\includes\admin.php:63
Maintenance & Trust

Accordion FAQ Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 19, 2025
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Accordion FAQ Developer Profile

elfsight

4 plugins · 5K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Accordion FAQ

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/elfsight-faq/assets/elfsight-faq.js/wp-content/plugins/elfsight-faq/assets/elfsight-admin.css/wp-content/plugins/elfsight-faq/assets/elfsight-admin.js/wp-content/plugins/elfsight-faq/preview/index.html/wp-content/plugins/elfsight-faq/preview/faq-observer.js
Script Paths
/wp-content/plugins/elfsight-faq/assets/elfsight-faq.js/wp-content/plugins/elfsight-faq/assets/elfsight-admin.js
Version Parameters
elfsight-faq/assets/elfsight-admin.css?ver=elfsight-faq/assets/elfsight-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
elfsight-adminelfsight-admin-wp-notifications-hackelfsight-admin-wrapperelfsight-admin-mainelfsight-admin-loadingelfsight-admin-loaderelfsight-admin-menu-containerelfsight-admin-pages-container
Data Attributes
data-elfsight-admin-slugdata-elfsight-admin-widgets-clogged
JS Globals
window.ElfsightFaqPluginwindow.ElfsightWidget
FAQ

Frequently Asked Questions about Accordion FAQ