
Master Accordion ( Former WP Awesome FAQ Plugin ) Security & Risk Analysis
wordpress.org/plugins/wp-awesome-faqBest WordPress Accordion Plugin for WordPress. Master Accordion re-branded with lots new features and customization options
Is Master Accordion ( Former WP Awesome FAQ Plugin ) Safe to Use in 2026?
Generally Safe
Score 85/100Master Accordion ( Former WP Awesome FAQ Plugin ) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-awesome-faq plugin, version 4.1.9, exhibits a generally strong security posture based on the provided static analysis. There are no recorded vulnerabilities in its history, and the code analysis reveals a commitment to secure coding practices. Notably, all SQL queries utilize prepared statements, and the plugin implements nonce and capability checks for its entry points. The attack surface is small and all identified entry points (shortcodes) are protected by capability checks, which is a positive sign.
However, a significant concern arises from the output escaping. With 77 total outputs, only 30% are properly escaped, leaving a substantial portion vulnerable to Cross-Site Scripting (XSS) attacks. This means that if an attacker can inject malicious script into a field that the plugin displays without proper sanitization, it could be executed in the browser of other users. The absence of taint analysis flows is not necessarily a weakness but indicates either that the analysis was not performed or that no problematic flows were detected, which is a good sign if the analysis was comprehensive.
In conclusion, while the plugin demonstrates good practices in handling SQL and securing entry points, the low rate of proper output escaping is a critical weakness. The lack of any historical vulnerabilities is encouraging, but it does not negate the risk posed by the identified XSS potential. Users should be aware of this XSS risk and consider whether the benefits of the plugin outweigh this specific security concern.
Key Concerns
- Low percentage of properly escaped output
Master Accordion ( Former WP Awesome FAQ Plugin ) Security Vulnerabilities
Master Accordion ( Former WP Awesome FAQ Plugin ) Code Analysis
Bundled Libraries
Output Escaping
Master Accordion ( Former WP Awesome FAQ Plugin ) Attack Surface
Shortcodes 2
WordPress Hooks 20
Maintenance & Trust
Master Accordion ( Former WP Awesome FAQ Plugin ) Maintenance & Trust
Maintenance Signals
Community Trust
Master Accordion ( Former WP Awesome FAQ Plugin ) Alternatives
BH FAQ
bh-faq
This plugin will be added Faq Option into your site. Very easy and nice plugin.If you had any problem to use this plugin. Please contact us.
MYFAQ Plugin
myfaq
A simple and beauty WordPress FAQ Plugin : ) , please use [my_faq] shortcode!
WP Awesome City Weather Report
wp-awesome-city-weather-report
WP Awesome City Weather Report is a Widget that displays a specified city weather Report
Accordion FAQ – Compatible With All Page Builder (Elementor, Gutenberg)
responsive-accordion-and-collapse
Accordion And Collapse is the most easiest drag & drop accordion builder for WordPress. You can add multiple accordion and collapse with this.
WP responsive FAQ with category plugin
sp-faq
A quick, easy way to add an responsive FAQs page. You can use this plugin as a jQuery UI accordion. Also work with Gutenberg shortcode block.
Master Accordion ( Former WP Awesome FAQ Plugin ) Developer Profile
45 plugins · 43K total installs
How We Detect Master Accordion ( Former WP Awesome FAQ Plugin )
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-awesome-faq/css/animate.css/wp-content/plugins/wp-awesome-faq/css/owl.carousel.min.css/wp-content/plugins/wp-awesome-faq/css/responsive.css/wp-content/plugins/wp-awesome-faq/css/style.css/wp-content/plugins/wp-awesome-faq/js/accordion.js/wp-content/plugins/wp-awesome-faq/js/animate.min.js/wp-content/plugins/wp-awesome-faq/js/frontend.js/wp-content/plugins/wp-awesome-faq/js/owl.carousel.min.js+1 more/wp-content/plugins/wp-awesome-faq/js/accordion.js/wp-content/plugins/wp-awesome-faq/js/frontend.js/wp-content/plugins/wp-awesome-faq/js/animate.min.js/wp-content/plugins/wp-awesome-faq/js/owl.carousel.min.js/wp-content/plugins/wp-awesome-faq/js/waypoints.min.js/wp-content/plugins/wp-awesome-faq/css/style.css?ver=/wp-content/plugins/wp-awesome-faq/css/animate.css?ver=/wp-content/plugins/wp-awesome-faq/css/owl.carousel.min.css?ver=/wp-content/plugins/wp-awesome-faq/css/responsive.css?ver=/wp-content/plugins/wp-awesome-faq/js/accordion.js?ver=/wp-content/plugins/wp-awesome-faq/js/frontend.js?ver=/wp-content/plugins/wp-awesome-faq/js/animate.min.js?ver=/wp-content/plugins/wp-awesome-faq/js/owl.carousel.min.js?ver=/wp-content/plugins/wp-awesome-faq/js/waypoints.min.js?ver=HTML / DOM Fingerprints
jt-maf-accordion-wrapperjt-maf-single-faqjt-maf-faq-titlejt-maf-faq-contentjt-maf-faq-icon-wrapjt-maf-faq-activemaf-accordion-content<!-- Accordion Wrapper Start --><!-- Accordion Body Start --><!-- Accordion Item Start --><!-- Accordion Header Start -->+3 moredata-accordion-iddata-maf-faq-iddata-maf-faq-settingsjt_maf_accordion_frontend[wp_faq][wp_awesome_faq]