
JHK FAQ Security & Risk Analysis
wordpress.org/plugins/jhk-faqJust another FAQ Plugin. Simple and flexible.
Is JHK FAQ Safe to Use in 2026?
Generally Safe
Score 92/100JHK FAQ has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The jhk-faq plugin version 2.2.0 exhibits a generally good security posture based on the provided static analysis. A significant strength is the complete absence of dangerous functions, raw SQL queries, unsanitized file operations, and external HTTP requests. All output is properly escaped, and all SQL queries utilize prepared statements, indicating robust data handling practices. The attack surface is also minimal, with only one shortcode and no AJAX handlers or REST API routes exposed without proper checks. The lack of any recorded vulnerabilities in its history further reinforces this positive assessment.
However, a notable concern arises from the complete absence of nonce checks and capability checks. While the current attack surface doesn't immediately leverage this, it represents a significant potential blind spot. Any future addition of AJAX handlers, REST API routes, or even new shortcode functionalities that process user-submitted data without these crucial security measures could easily introduce vulnerabilities. This makes the plugin susceptible to CSRF attacks if functionality is added that performs sensitive actions without proper authorization verification. Therefore, while the current state is secure, there's a proactive risk of future vulnerabilities due to these missing fundamental security checks.
Key Concerns
- Missing nonce checks
- Missing capability checks
JHK FAQ Security Vulnerabilities
JHK FAQ Code Analysis
Output Escaping
JHK FAQ Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
JHK FAQ Maintenance & Trust
Maintenance Signals
Community Trust
JHK FAQ Alternatives
Meks Flexible Shortcodes
meks-flexible-shortcodes
Add some cool elements to your post/page content with flexible shortcodes.
Gutena Accordion – Beautiful FAQ Accordion Block
gutena-accordion
Gutena Accordion is a WordPress Plugin which makes accordion dropdown creation really easy inside the block editor. Furthermore, it is very light weig …
SFN Easy FAQ Manager
wordpress-faq-manager
Uses custom post types and taxonomies to manage an FAQ section for your site.
FAQ Manager For Divi, Gutenberg Block & Shortcode
faq-manager-with-structured-data
Easily create, manage bookmarkable FAQs on your website. Use divi module, FAQ block or shortcode to display FAQs. Boost SEO with FAQPage schema & …
FAQ Builder AYS
faq-builder-ays
Create FAQs and accordions for your WP website without effort with FAQ Builder. Has Gutenberg Block, responsive design, 20+ style options, etc.
JHK FAQ Developer Profile
2 plugins · 0 total installs
How We Detect JHK FAQ
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/jhk-faq/assets/css/jhkfaqp-front-custom.css/wp-content/plugins/jhk-faq/assets/js/jhkfaqp-front-custom.jsHTML / DOM Fingerprints
jhkfaqp-wrapperjhkfaqp-faq-itemjhkfaqp-questionjhkfaqp-answerFAQ Shortcodedata-layoutjhkfaqp_global_vars[jhk-faq][jhk-faq category="your-category"][jhk-faq tag="your-tag"][jhk-faq layout="layout-name"]