
LR Faq Security & Risk Analysis
wordpress.org/plugins/lr-faqLR Faq to the admin panel which allows you to show your faq on your website the easy with deffernt styles
Is LR Faq Safe to Use in 2026?
Generally Safe
Score 100/100LR Faq has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "lr-faq" v1.4 plugin exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, file operations, external HTTP requests, and the use of prepared statements for all SQL queries are strong indicators of secure coding practices. Furthermore, the plugin has no recorded vulnerabilities, including no known CVEs, which suggests a history of security awareness from the developers.
However, there are areas of concern. The most significant is the low percentage (43%) of properly escaped output. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled with sufficient sanitization before being displayed. The lack of nonce checks and capability checks, while noted as 0 entry points requiring them, means that if future functionality introduces AJAX handlers or other sensitive endpoints, these critical security mechanisms are currently absent. The single shortcode, while not reported as a risk, represents a potential entry point that could be exploited if not properly secured, especially in conjunction with the output escaping issue.
In conclusion, while the plugin avoids many common pitfalls and has a clean vulnerability history, the significant amount of unescaped output is a notable weakness that could lead to XSS attacks. Developers should prioritize addressing this by implementing robust output sanitization for all dynamic content. The absence of nonce and capability checks on existing or future functionalities also warrants attention to prevent unauthorized actions or privilege escalation.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks implemented
- No capability checks implemented
LR Faq Security Vulnerabilities
LR Faq Release Timeline
LR Faq Code Analysis
Output Escaping
LR Faq Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
LR Faq Maintenance & Trust
Maintenance Signals
Community Trust
LR Faq Alternatives
FAQ Concertina
faq-concertina
Display FAQs in an expandable concertina or accordion section. FAQs can be ordered and categorised, and their appearance can be customised.
FAQ Manager For Divi, Gutenberg Block & Shortcode
faq-manager-with-structured-data
Easily create, manage bookmarkable FAQs on your website. Use divi module, FAQ block or shortcode to display FAQs. Boost SEO with FAQPage schema & …
FAQ Builder AYS
faq-builder-ays
Create FAQs and accordions for your WP website without effort with FAQ Builder. Has Gutenberg Block, responsive design, 20+ style options, etc.
Faq Module For Divi
faq-module-for-divi
Faq Module For Divi plugin is depreciated. Use our https://wordpress.org/plugins/faq-manager-with-structured-data/ plugin that has latest faq divi mod …
AD Sliding FAQ
ad-sliding-faq
Create a nice and accessible accordion FAQ section with sliding Q/A.
LR Faq Developer Profile
16 plugins · 190 total installs
How We Detect LR Faq
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lr-faq/css/style.css/wp-content/plugins/lr-faq/js/script.js/wp-content/plugins/lr-faq/css/lr-faq-style-one.css/wp-content/plugins/lr-faq/css/lr-faq-style-two.css/wp-content/plugins/lr-faq/css/lr-faq-style-three.css/wp-content/plugins/lr-faq/css/lr-faq-style-four.css/wp-content/plugins/lr-faq/css/lr-faq-style-five.css/wp-content/plugins/lr-faq/css/lr-faq-style-six.css/wp-content/plugins/lr-faq/js/script.jslr-faq/css/style.css?ver=lr-faq/js/script.js?ver=HTML / DOM Fingerprints
lr-faq-accordionlr-faq-itemlr-faq-questionlr-faq-answerlr-faq-headinglr-switchlr-sliderlr-faq-settings-contentdata-lr-faq-styleLR_FAQ_PLUGIN_URLupdateFaqPreview[LRFAQ]