My WP FAQs Security & Risk Analysis

wordpress.org/plugins/my-wp-faqs-list

This plugin will add FAQs list feature inside a post or page.

10 active installs v1.0 PHP + WP 3.0.1+ Updated Nov 11, 2015
awesome-faqsbootstrap-faqsjquery-faqspost-faqs-list
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is My WP FAQs Safe to Use in 2026?

Generally Safe

Score 85/100

My WP FAQs has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "my-wp-faqs-list" v1.0 plugin exhibits a strong security posture. The code analysis reveals no dangerous functions, no raw SQL queries, and all output is properly escaped. Furthermore, there are no file operations or external HTTP requests, and importantly, the plugin has a clean vulnerability history with zero known CVEs. This indicates a well-developed and secure piece of code.

However, there are a few areas that warrant attention for future development. The absence of any nonce checks or capability checks across all entry points, including the single shortcode, presents a potential weakness. While the current attack surface is small and there are no identified unsanitized taint flows, this lack of authorization checks could become a significant vulnerability if any new features are added that handle user-supplied data or perform sensitive operations.

In conclusion, "my-wp-faqs-list" v1.0 is currently very secure due to its clean code and lack of historical vulnerabilities. Its strengths lie in its adherence to secure coding practices regarding SQL and output escaping. The primary weakness lies in the lack of authorization mechanisms on its single entry point, which, while not an immediate critical flaw given the current features, represents a potential future risk if the plugin evolves.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

My WP FAQs Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

My WP FAQs Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

My WP FAQs Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[faq] main-functions.php:89
WordPress Hooks 4
actioninitmain-functions.php:13
actioninitmain-functions.php:21
actionwp_headmain-functions.php:38
actioninitmain-functions.php:93
Maintenance & Trust

My WP FAQs Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedNov 11, 2015
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Alternatives

My WP FAQs Alternatives

No alternatives data available yet.

Developer Profile

My WP FAQs Developer Profile

Sohelwpexpert

10 plugins · 190 total installs

78
trust score
Avg Security Score
86/100
Avg Patch Time
50 days
View full developer profile
Detection Fingerprints

How We Detect My WP FAQs

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/my-wp-faqs-list/js/bootstrap.js/wp-content/plugins/my-wp-faqs-list/css/bootstrap.css/wp-content/plugins/my-wp-faqs-list/style.css
Script Paths
/wp-content/plugins/my-wp-faqs-list/js/bootstrap.js
Version Parameters
my-wp-faqs-list/js/bootstrap.js?ver=my-wp-faqs-list/css/bootstrap.css?ver=my-wp-faqs-list/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
accordionfaqtoggleaccordion-itemaccordion-headingaccordion-titleaccordion-collapsecollapse+1 more
Data Attributes
data-toggle="collapse"href="#collapse
JS Globals
jQuery
Shortcode Output
<div class="accordion faq toggle">
FAQ

Frequently Asked Questions about My WP FAQs