ZPLMOd – FAQ Lite Security & Risk Analysis

wordpress.org/plugins/zplmod-faq-lite

A WordPress Plugin : FAQ.Lite, it easy for you to FAQs on your site add using shortcode, fully compatible with all responsive themes and reduce databa …

0 active installs v1.7.24 PHP + WP 4.0+ Updated Jul 23, 2017
faqfaq-widgetfaqsfrequently-asked-questionswoocommerce-faq
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ZPLMOd – FAQ Lite Safe to Use in 2026?

Generally Safe

Score 85/100

ZPLMOd – FAQ Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The plugin 'zplmod-faq-lite' v1.7.24 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, SQL queries, file operations, external HTTP requests, and the use of prepared statements for all SQL queries are positive indicators. Furthermore, the plugin has no recorded vulnerabilities (CVEs), which suggests a history of secure development or diligent patching by maintainers. The limited attack surface, consisting of two shortcodes with no readily apparent unprotected entry points, further contributes to its positive security profile.

However, there are significant concerns regarding output escaping. With three total outputs analyzed and 0% properly escaped, this presents a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed to users, especially if it originates from user input or external sources, could be exploited to inject malicious scripts. Additionally, the complete lack of nonce and capability checks is a notable weakness, particularly if the shortcodes handle sensitive operations or display user-specific data. While the static analysis did not reveal any specific taint flows or unprotected entry points, the unescaped output and lack of authorization checks create an environment where such vulnerabilities could easily be introduced or exploited.

In conclusion, while the plugin benefits from a clean vulnerability history and a small attack surface with secure SQL handling, the critical issue of unescaped output and the absence of essential security checks like nonces and capability checks significantly lower its overall security score. Developers should prioritize addressing the output escaping and implementing proper authorization mechanisms to mitigate potential XSS and privilege escalation risks.

Key Concerns

  • Unescaped output across all analyzed outputs
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

ZPLMOd – FAQ Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ZPLMOd – FAQ Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped3 total outputs
Attack Surface

ZPLMOd – FAQ Lite Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[faqlite] zplmod-faqlite.php:89
[faqlite_tab] zplmod-faqlite.php:90
WordPress Hooks 2
actionadmin_menuzplmod-faqlite.php:23
actionwp_footerzplmod-faqlite.php:40
Maintenance & Trust

ZPLMOd – FAQ Lite Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedJul 23, 2017
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

ZPLMOd – FAQ Lite Developer Profile

Naksheth Surabhi

2 plugins · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ZPLMOd – FAQ Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zplmod-faq-lite/css/zplmod-faqlite.css/wp-content/plugins/zplmod-faq-lite/js/zplmod-faqlite.js
Script Paths
/wp-content/plugins/zplmod-faq-lite/js/zplmod-faqlite.js
Version Parameters
zplmod-faq-lite/css/zplmod-faqlite.css?ver=zplmod-faq-lite/js/zplmod-faqlite.js?ver=

HTML / DOM Fingerprints

CSS Classes
faqlite-titlefaqlite-contentfaqlite-entryfaqlite-listfaqlite-headerclose-faqopen-faq
HTML Comments
/* faqlite jquery */<!-- Tab 1 : #General -->
Data Attributes
data-content-id
Shortcode Output
<div class="faqlite-list"><h2 class="faqlite-header"><article class="faqlite-entry"<h3 class="faqlite-title close-faq"
FAQ

Frequently Asked Questions about ZPLMOd – FAQ Lite