Quick and Easy FAQs Security & Risk Analysis

wordpress.org/plugins/quick-and-easy-faqs

Truly a quick and easy way to add FAQs to your site.

10K active installs v1.3.14 PHP 8.3+ WP 6.0+ Updated Dec 4, 2025
accordion-faqsfaqfaqsfiltered-faqsgutenberg-faqs
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Quick and Easy FAQs Safe to Use in 2026?

Generally Safe

Score 100/100

Quick and Easy FAQs has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The plugin "quick-and-easy-faqs" v1.3.14 exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, cron events, file operations, and external HTTP requests significantly limits the potential attack surface. Furthermore, all SQL queries are properly prepared, and there are no reported critical or high-severity vulnerabilities in its history. The code signals indicate a good effort towards secure coding practices, with a majority of outputs being properly escaped. However, there are some areas that warrant attention. The presence of a shortcode as the sole entry point, while not directly identified as unprotected in this analysis, represents a potential area for future vulnerabilities if not handled with care. The lack of explicit nonce checks and capability checks is a concern, as these are fundamental WordPress security mechanisms that help prevent Cross-Site Request Forgery (CSRF) and unauthorized actions. While the taint analysis shows no critical or high severity unsanitized paths, the absence of any analyzed flows limits the confidence in this assessment.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Limited taint flow analysis
  • Shortcode as the only entry point
Vulnerabilities
None known

Quick and Easy FAQs Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Quick and Easy FAQs Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
18
45 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

71% escaped63 total outputs
Attack Surface

Quick and Easy FAQs Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[faqs] frontend\class-shortcode.php:129
WordPress Hooks 17
actionplugins_loadedincludes\class-faqs.php:51
actioninitincludes\class-faqs.php:84
actioninitincludes\class-faqs.php:85
actionadmin_enqueue_scriptsincludes\class-faqs.php:88
actionadmin_enqueue_scriptsincludes\class-faqs.php:89
filtermce_external_pluginsincludes\class-faqs.php:92
filtermce_buttonsincludes\class-faqs.php:93
filterblock_categories_allincludes\class-faqs.php:97
actioninitincludes\class-faqs.php:98
actionadmin_menuincludes\class-faqs.php:102
actionadmin_menuincludes\class-faqs.php:103
actionwp_enqueue_scriptsincludes\class-faqs.php:115
actionwp_enqueue_scriptsincludes\class-faqs.php:116
actionwp_enqueue_scriptsincludes\class-faqs.php:117
actioninitincludes\class-faqs.php:120
actionvc_before_initincludes\class-faqs.php:123
actionadmin_enqueue_scriptsincludes\class-settings-api.php:25
Maintenance & Trust

Quick and Easy FAQs Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 4, 2025
PHP min version8.3
Downloads419K

Community Trust

Rating92/100
Number of ratings36
Active installs10K
Developer Profile

Quick and Easy FAQs Developer Profile

Inspiry Themes

7 plugins · 17K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Quick and Easy FAQs

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Quick and Easy FAQs