FAQ Plus – WordPress FAQ Plugin Security & Risk Analysis

wordpress.org/plugins/faq-plus

WordPress FAQ Plugin helps you to easily display frequently asked questions on your WordPress website without coding.

10 active installs v1.0.0 PHP 5.6+ WP 4.9+ Updated Jul 3, 2025
faqfaq-pluginfaq-schemaschema
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FAQ Plus – WordPress FAQ Plugin Safe to Use in 2026?

Generally Safe

Score 100/100

FAQ Plus – WordPress FAQ Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The "faq-plus" v1.0.0 plugin exhibits a generally good security posture, with no known vulnerabilities or CVEs recorded. The static analysis shows no direct attack surface points like unprotected AJAX handlers or REST API routes. Additionally, the plugin avoids dangerous functions, file operations, and external HTTP requests, which are common vectors for exploits. The use of prepared statements for all SQL queries is a significant strength, mitigating the risk of SQL injection vulnerabilities.

However, there are areas for improvement. A concerning signal from the taint analysis is the presence of "flows with unsanitized paths," even though they are not classified as critical or high severity. This suggests that while paths are not directly exploitable in this version, there's a potential for unexpected behavior or a precursor to future vulnerabilities if not addressed. The output escaping is also only 65% proper, meaning a portion of the output is not being sanitized, potentially leading to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully. The absence of nonce and capability checks on the identified shortcode entry point is another notable concern, as it allows any user, regardless of their role or intent, to potentially trigger the shortcode's functionality.

Key Concerns

  • Unsanitized paths in taint flows
  • Insufficient output escaping
  • Missing nonce checks on shortcode
  • Missing capability checks on shortcode
Vulnerabilities
None known

FAQ Plus – WordPress FAQ Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

FAQ Plus – WordPress FAQ Plugin Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

FAQ Plus – WordPress FAQ Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
26 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

65% escaped40 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
nikan_faqp_settings_saved (includes/admin_faqp_menu.php:24)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

FAQ Plus – WordPress FAQ Plugin Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[faqp] includes/faqp_admin_functions.php:280
WordPress Hooks 11
actioninitfaq-plus.php:25
actionadmin_menuincludes/admin_faqp_menu.php:5
actioninitincludes/admin_faqp_post_type_tax.php:5
actionmanage_faqp_posts_columnsincludes/admin_faqp_post_type_tax.php:53
actionmanage_faqp_posts_custom_columnincludes/admin_faqp_post_type_tax.php:62
actionadmin_enqueue_scriptsincludes/faqp_admin_functions.php:5
actionadd_meta_boxesincludes/faqp_admin_functions.php:47
actionsave_postincludes/faqp_admin_functions.php:182
actionwp_footerincludes/faqp_admin_functions.php:217
actionwp_footerincludes/faqp_admin_functions.php:240
actionwp_footerincludes/faqp_admin_functions.php:260
Maintenance & Trust

FAQ Plus – WordPress FAQ Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedJul 3, 2025
PHP min version5.6
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

FAQ Plus – WordPress FAQ Plugin Developer Profile

نیکان وردپرس

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect FAQ Plus – WordPress FAQ Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/faq-plus/assets/css/admin_faqp.css/wp-content/plugins/faq-plus/assets/js/admin_nikan_faqp.js
Script Paths
assets/js/admin_nikan_faqp.js

HTML / DOM Fingerprints

CSS Classes
nikan_faqp_faqp_display_typenikan_faqpsnikan_faqp_dropmenikan_faqp_rownikan_faqp_remove_rownikan_faqp_accordionnikan_faqp_open_rownikan_faqp_form_row+3 more
Data Attributes
name="nikan_faqp_question[]"name="nikan_faqp_answer[]"name="faqp_display_type"
JS Globals
nikan_faqp_object
FAQ

Frequently Asked Questions about FAQ Plus – WordPress FAQ Plugin