Product FAQs Manager Security & Risk Analysis

wordpress.org/plugins/product-faq-manager

Product FAQs Manager helps store owners manage FAQs on product pages to improve user experience and increase conversions.

0 active installs v1.0.1 PHP 5.6+ WP 4.4+ Updated Jan 4, 2025
faqfaqsfaqs-managerproduct-faqswoocommerce-faq
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Product FAQs Manager Safe to Use in 2026?

Generally Safe

Score 92/100

Product FAQs Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "product-faq-manager" v1.0.1 plugin exhibits a strong security posture based on the provided static analysis. It boasts no known CVEs, zero critical or high severity taint flows, and all SQL queries utilize prepared statements, which are excellent indicators of secure coding practices. The plugin also demonstrates good output escaping with 78% of outputs properly handled, and includes nonce checks, further bolstering its defenses.

However, a key area of concern is the complete absence of capability checks (0 recorded). This means that while nonce checks might be in place, there are no checks to ensure that a logged-in user has the necessary WordPress role or capability to perform an action. This could potentially lead to privilege escalation if an attacker can bypass other authentication mechanisms or exploit a logic flaw. The 2 REST API routes, while having permission callbacks, still represent entry points that require careful scrutiny to ensure those callbacks are robust and correctly implemented.

In conclusion, the plugin has a solid foundation in preventing common vulnerabilities like SQL injection and cross-site scripting. The lack of vulnerability history is a positive sign of its reliability. The primary weakness lies in the missing capability checks, which is a significant oversight that could expose functionality to unauthorized users. Addressing this would elevate the plugin's security considerably.

Key Concerns

  • Missing capability checks
  • REST API routes without explicit auth checks in static analysis
  • Output escaping not 100%
Vulnerabilities
None known

Product FAQs Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Product FAQs Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
35 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

78% escaped45 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
pfaqm_tab_data_panels (includes\Admin\Product_Faq_Backend.php:29)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Product FAQs Manager Attack Surface

Entry Points2
Unprotected0

REST API Routes 2

POST/wp-json/product-faq-manager/v1/set-faqincludes\Rest_API.php:55
POST/wp-json/product-faq-manager/v1/get-faqincludes\Rest_API.php:84
WordPress Hooks 12
actionadd_meta_boxesincludes\Admin\Metaboxes.php:40
actionsave_postincludes\Admin\Metaboxes.php:41
actionwoocommerce_product_data_panelsincludes\Admin\Product_Faq_Backend.php:24
filterwoocommerce_product_data_tabsincludes\Admin\Product_Faq_Backend.php:25
actioninitincludes\Admin\Product_Faq_Backend.php:26
actioninitincludes\Admin\Product_Faq_Settings.php:21
actionadmin_enqueue_scriptsincludes\Enqueue.php:28
actionwp_enqueue_scriptsincludes\Enqueue.php:29
filterwoocommerce_product_tabsincludes\Product_Faq_Frontend.php:41
actionrest_api_initincludes\Rest_API.php:43
actioninitproduct-faq-manager.php:88
actionplugins_loadedproduct-faq-manager.php:89
Maintenance & Trust

Product FAQs Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedJan 4, 2025
PHP min version5.6
Downloads877

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Product FAQs Manager Developer Profile

Nazmun Sakib

5 plugins · 10 total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Product FAQs Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/product-faq-manager/assets/css/admin.css/wp-content/plugins/product-faq-manager/assets/css/multi-select.css/wp-content/plugins/product-faq-manager/assets/js/admin.js/wp-content/plugins/product-faq-manager/assets/js/multi-select.js
Script Paths
pfaqm-multi-selectpfaqm-multi-selectpfaqm-adminpfaqm-admin
Version Parameters
product-faq-manager/assets/css/admin.css?ver=product-faq-manager/assets/css/multi-select.css?ver=product-faq-manager/assets/js/admin.js?ver=product-faq-manager/assets/js/multi-select.js?ver=

HTML / DOM Fingerprints

CSS Classes
pfaqm-faq-metabox-wrapperpfaqm-faq-metabox-tablepfaqm-faq-metabox-row
Data Attributes
data-placeholderdata-multi-select
FAQ

Frequently Asked Questions about Product FAQs Manager