WPFY FAQ Block Security & Risk Analysis

wordpress.org/plugins/wpfy-faq-block

Gutenberg Block plugin for Frequently Asked Questions (FAQ) feature. Very straight forward to use. Just install and enjoy.

0 active installs v1.0 PHP 7.0+ WP 4.7+ Updated Oct 5, 2022
blockfaqfrequently-asked-questionsgutenbergwordpress-plugin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPFY FAQ Block Safe to Use in 2026?

Generally Safe

Score 85/100

WPFY FAQ Block has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The plugin 'wpfy-faq-block' v1.0 exhibits a strong security posture based on the provided static analysis. The absence of detectable AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code signals indicate a lack of dangerous functions, proper SQL prepared statement usage, and file operations. The absence of external HTTP requests and taint analysis results showing no unsanitized flows are also positive indicators. The plugin's vulnerability history is clean, with no recorded CVEs, suggesting a proactive approach to security or a lack of previous issues. However, the lack of capability checks and nonce checks, coupled with a moderate percentage of improperly escaped outputs, represent potential weaknesses that could be exploited if an attack vector were to be discovered. Overall, the plugin is well-developed from a security standpoint, but these minor areas warrant attention for further hardening.

Key Concerns

  • Capability checks are missing
  • Nonce checks are missing
  • Some outputs are not properly escaped
Vulnerabilities
None known

WPFY FAQ Block Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WPFY FAQ Block Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

80% escaped5 total outputs
Attack Surface

WPFY FAQ Block Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_menuwpfy-scroller.php:23
actionadmin_initwpfy-scroller.php:24
actionwp_enqueue_scriptswpfy-scroller.php:25
actionwp_footerwpfy-scroller.php:28
actionadmin_enqueue_scriptswpfy-scroller.php:31
Maintenance & Trust

WPFY FAQ Block Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedOct 5, 2022
PHP min version7.0
Downloads684

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

WPFY FAQ Block Developer Profile

Akramul Hasan

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WPFY FAQ Block

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpfy-scroller/assets/css/style.css/wp-content/plugins/wpfy-scroller/assets/js/scroll-main.js/wp-content/plugins/wpfy-scroller/assets/js/colorPicker.js
Script Paths
/wp-content/plugins/wpfy-scroller/assets/js/scroll-main.js/wp-content/plugins/wpfy-scroller/assets/js/colorPicker.js

HTML / DOM Fingerprints

CSS Classes
topbuttonicon-wraptop-icon
Data Attributes
class="topbutton"class="icon-wrap"class="top-icon"
FAQ

Frequently Asked Questions about WPFY FAQ Block