Awesome FAQ – Modern Accordion, Tabs,Responsive & Super Fast FAQ Builder. Security & Risk Analysis

wordpress.org/plugins/faq-and-answers

Create responsive FAQ sections, toggle content, and multiple accordion-style question groups effortlessly on your WordPress site.

400 active installs v2.0.5 PHP 7.1+ WP 6.5+ Updated Mar 12, 2026
accordionblockfaq-blockgutenberg-blocktoggle
99
A · Safe
CVEs total1
Unpatched0
Last CVEDec 11, 2024
Download
Safety Verdict

Is Awesome FAQ – Modern Accordion, Tabs,Responsive & Super Fast FAQ Builder. Safe to Use in 2026?

Generally Safe

Score 99/100

Awesome FAQ – Modern Accordion, Tabs,Responsive & Super Fast FAQ Builder. has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Dec 11, 2024Updated 22d ago
Risk Assessment

The "faq-and-answers" plugin version 2.0.5 demonstrates a generally strong security posture based on the static analysis. The absence of dangerous functions, use of prepared statements for all SQL queries, and proper output escaping are excellent security practices. The plugin also appears to have no external HTTP requests or file operations, further reducing its attack surface. However, the static analysis reveals a concerning lack of security checks. Specifically, there are no nonce checks or capability checks implemented, despite having one shortcode entry point. While the taint analysis found no issues, the absence of these checks on the shortcode means that any input processed by it could potentially be manipulated if not handled internally with extreme care, even if the direct taint flow wasn't detected in this analysis. The vulnerability history shows one past medium-severity Cross-Site Scripting (XSS) vulnerability, which, although patched, indicates a potential for such issues. The fact that it was a medium severity XSS in the past and there are no capability checks on the shortcode is a significant concern.

While the plugin's adherence to secure coding practices for SQL and output is commendable, the lack of authentication and authorization checks on its entry points, particularly the shortcode, presents a notable risk. The past XSS vulnerability, coupled with the missing checks, suggests a need for more robust security measures to protect against potential input manipulation and privilege escalation. The bundling of Freemius, while not inherently a security flaw, should be monitored for any potential vulnerabilities within the bundled library itself. Overall, the plugin has strengths in its secure handling of data processing but weaknesses in input validation and access control, warranting cautious use.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
  • Past medium severity XSS vulnerability
  • Bundled Freemius library
Vulnerabilities
1

Awesome FAQ – Modern Accordion, Tabs,Responsive & Super Fast FAQ Builder. Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-11882medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

FAQ And Answers – Create Frequently Asked Questions Area on WP Sites <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 11, 2024 Patched in 1.1.2 (1d)
Code Analysis
Analyzed Mar 16, 2026

Awesome FAQ – Modern Accordion, Tabs,Responsive & Super Fast FAQ Builder. Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius

Output Escaping

100% escaped6 total outputs
Attack Surface

Awesome FAQ – Modern Accordion, Tabs,Responsive & Super Fast FAQ Builder. Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[faq] includes\class_faaPlugin.php:9
WordPress Hooks 9
actioninitfaq-and-answers-block.php:7
actionenqueue_block_editor_assetsfaq-and-answers-block.php:8
actionenqueue_block_assetsfaq-and-answers-block.php:9
actioninitincludes\class_faaAdmin.php:7
actionadmin_menuincludes\class_faaAdmin.php:8
filtermanage_faq_cpt_posts_columnsincludes\class_faaAdmin.php:9
actionmanage_faq_cpt_posts_custom_columnincludes\class_faaAdmin.php:10
actionplugins_loadedincludes\class_faaPlugin.php:7
actionadmin_enqueue_scriptsincludes\class_faaPlugin.php:8
Maintenance & Trust

Awesome FAQ – Modern Accordion, Tabs,Responsive & Super Fast FAQ Builder. Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 12, 2026
PHP min version7.1
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs400
Developer Profile

Awesome FAQ – Modern Accordion, Tabs,Responsive & Super Fast FAQ Builder. Developer Profile

colorlibplugins

120 plugins · 738K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
140 days
View full developer profile
Detection Fingerprints

How We Detect Awesome FAQ – Modern Accordion, Tabs,Responsive & Super Fast FAQ Builder.

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/faq-and-answers/build/shortcode.css/wp-content/plugins/faq-and-answers/build/admin-dashboard.css
Script Paths
/wp-content/plugins/faq-and-answers/build/shortcode.js/wp-content/plugins/faq-and-answers/build/admin-dashboard.js
Version Parameters
faq-and-answers/build/shortcode.css?ver=faq-and-answers/build/shortcode.js?ver=faq-and-answers/build/admin-dashboard.css?ver=faq-and-answers/build/admin-dashboard.js?ver=

HTML / DOM Fingerprints

CSS Classes
faa-faq-wrapperfaa-questionfaa-answer
Data Attributes
data-faq-id
JS Globals
faa_fs
Shortcode Output
<p>Error: Awesome FAQ block with ID not found.</p>
FAQ

Frequently Asked Questions about Awesome FAQ – Modern Accordion, Tabs,Responsive & Super Fast FAQ Builder.