FAQ ZYREX Security & Risk Analysis

wordpress.org/plugins/faq-zyrex

Lightweight FAQ accordion that boosts your SEO with Google rich snippets. 6 languages, full styling control, zero bloat.

0 active installs v2.1.1 PHP 7.4+ WP 6.3+ Updated May 21, 2026
accordionfaqfaq-schemagutenberg-blockrich-snippets
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FAQ ZYREX Safe to Use in 2026?

Generally Safe

Score 100/100

FAQ ZYREX has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "faq-zyrex" plugin version 1.1 exhibits a generally positive security posture with no publicly known vulnerabilities. Static analysis reveals good practices in output escaping, with all 20 outputs properly escaped. The plugin also avoids dangerous functions, file operations, and external HTTP requests. However, the analysis does highlight a couple of areas for concern. The presence of 2 taint flows with unsanitized paths, although not categorized as critical or high severity, warrants attention as it suggests potential avenues for unexpected behavior or data manipulation if user input is not handled with extreme care. Furthermore, the complete absence of nonce checks and capability checks across all entry points, including the shortcode, is a significant weakness. This implies that even authenticated users might be able to trigger unintended actions or access sensitive data through the shortcode, increasing the attack surface for privilege escalation or unauthorized modifications.

Key Concerns

  • Unsanitized taint flows found
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

FAQ ZYREX Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

FAQ ZYREX Release Timeline

v2.1.1Current
v2.1.0
v2.0.1
v2.0.0
v1.1
v1.0
Code Analysis
Analyzed Mar 17, 2026

FAQ ZYREX Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
4 prepared
Unescaped Output
0
20 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

67% prepared6 total queries

Output Escaping

100% escaped20 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
zx_main_page (class\class.php:17)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

FAQ ZYREX Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[zxfaq] zx-faq.php:81
WordPress Hooks 2
actionadmin_menuclass\class.php:10
actionwp_enqueue_scriptszx-faq.php:19
Maintenance & Trust

FAQ ZYREX Maintenance & Trust

Maintenance Signals

WordPress version tested7.0.2
Last updatedMay 21, 2026
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

FAQ ZYREX Developer Profile

Zyrex

2 plugins · 10 total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
294 days
View full developer profile
Detection Fingerprints

How We Detect FAQ ZYREX

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/faq-zyrex/css/main.css
Version Parameters
faq-zyrex/css/main.css?ver=

HTML / DOM Fingerprints

CSS Classes
accordionsaccordionacc-labelacc-content
Data Attributes
for="faqid="faq
Shortcode Output
<div class="accordions"><div class="accordion"><input type="checkbox" id="faq<label for="faq
FAQ

Frequently Asked Questions about FAQ ZYREX