Atlas / MCP servers / thorsten / PhpMyFAQ

PhpMyFAQBLOCK

mcp/thorsten/phpmyfaq

phpMyFAQ - Open Source FAQ web application for PHP 8.4+ and MySQL, PostgreSQL and other databases

Verdict
BLOCK
Grade
F
Trust score
42 /100
Exposed tools
17 16r · 1w · 0d
Transport
—
License
MPL-2.0
Stars
621
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://phpmyfaq.readthedocs.io/en/latest/?badge=latest)

What is phpMyFAQ?

phpMyFAQ is a multilingual, AI-ready, and scalable FAQ platform built for modern knowledge management. Powered by PHP 8.4+ and a fully database-driven architecture, it delivers fast search with Elasticsearch/OpenSearch, flexible multi-user permissions, and a powerful content management system with revision history and WYSIWYG editing.

With 40+ languages, responsive Twig-based templates, a REST API, 2FA security, enterprise authentication (LDAP, Active Directory, Entra ID), and a built-in plugin system, phpMyFAQ integrates seamlessly into almost any environment.

Deploy it on traditional hosting or run it in the cloud via Docker.

Requirements

phpMyFAQ requires PHP 8.4 or higher and a supported database system. Supported databases include MySQL, MariaDB, Percona Server, PostgreSQL, Microsoft SQL Server, and SQLite3.

For enhanced search capabilities using Elasticsearch or OpenSearch, Elasticsearch 8.x or later or OpenSearch 2.x or later is required.

For a complete and up-to-date list of system requirements, please refer to the official documentation at phpmyfaq.de.

Installation

phpMyFAQ installation package for end-users

The best way to install phpMyFAQ is to download it on phpmyfaq.de, unzip the package, and open http://www.example.org/phpmyfaq/setup/ in your preferred browser.

phpMyFAQ installation with Docker

Production images

Every release is published to the GitHub Container Registry as ghcr.io/thorsten/phpmyfaq: (Apach

Read from source at commit 9ca9c1255fa4OBSERVED · 2026-09-28
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add phpmyfaq --env E2E_ADMIN_PASSWORD=${E2E_ADMIN_PASSWORD} -- npx -y @thorsten/[email protected]
claude-desktop
{
  "mcpServers": {
    "phpmyfaq": {
      "command": "npx",
      "args": [
        "-y",
        "@thorsten/[email protected]"
      ],
      "env": {
        "E2E_ADMIN_PASSWORD": "${E2E_ADMIN_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (17)

16 read · 1 write · 0 destructive.

ToolRiskDescription
AdminsreadAdmin group
EditorsreadEditorial team
categoryIdreadThe category ID.
faqIdreadThe FAQ record ID.
faq_searchreadSearch through the phpMyFAQ knowledge base to find relevant FAQ entries that can answer questions.
limitreadAlternative to per_page for offset-based pagination
minimal_toolreadMinimal tool
offsetreadOffset for pagination (overrides page parameter)
orderwriteSort order
pagereadPage number for pagination (1-indexed)
per_pagereadNumber of items per page
qreadThe search term
sortreadField to sort by
tagIdreadThe tag ID.
test_toolreadA test tool
toolreaddesc
typereadThe backup type. Can be
04

Trust audit

BLOCKgrade F · trust 42/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (10 observation(s))
Network
declared (7 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
phpmyfaq/src/phpMyFAQ/Configuration/Storage/RedisConfigurationStore.php:164
$results = $redis->exec();
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
phpmyfaq/src/phpMyFAQ/Instance/Database/PdoSqlsrv.php:411
"IF NOT EXISTS (SELECT * FROM sys.schemas WHERE name = '%s') EXEC('CREATE SCHEMA %s')",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
phpmyfaq/src/phpMyFAQ/Instance/Database/Sqlsrv.php:412
"IF NOT EXISTS (SELECT * FROM sys.schemas WHERE name = '%s') EXEC('CREATE SCHEMA %s')",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
phpmyfaq/src/phpMyFAQ/Setup/Installation/SchemaInstaller.php:135
"IF NOT EXISTS (SELECT * FROM sys.schemas WHERE name = '%s') EXEC('CREATE SCHEMA [%s]')",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
phpmyfaq/src/phpMyFAQ/Setup/Migration/Versions/Migration420Alpha2.php:301
. "EXEC('ALTER TABLE %s DROP CONSTRAINT ' + @constraintName)",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInventory / provenance · inv.binary · CWE-1104
phpmyfaq/src/fonts/dejavu/dejavumathtexgyre.ctg.z
dejavumathtexgyre.ctg.z
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
phpmyfaq/src/fonts/dejavu/dejavumathtexgyre.z
dejavumathtexgyre.z
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
phpmyfaq/src/fonts/dejavu/dejavusans.ctg.z
dejavusans.ctg.z
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
phpmyfaq/src/fonts/dejavu/dejavusans.z
dejavusans.z
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
phpmyfaq/src/fonts/dejavu/dejavusansb.ctg.z
dejavusansb.ctg.z
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
phpmyfaq/.env.example:72
OPENSEARCH_BASE_URI=http://127.0.0.1:9201
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
phpmyfaq/.env.example:73
ELASTICSEARCH_BASE_URI=http://127.0.0.1:9200
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
phpmyfaq/src/phpMyFAQ/Instance/Database/Stopwords.php:3185
"INSERT INTO %sfaqstopwords (id, lang, stopword) VALUES (3151, 'tr', 'k√Ωrk')",
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
phpmyfaq/src/phpMyFAQ/Instance/Database/Stopwords.php:3191
"INSERT INTO %sfaqstopwords (id, lang, stopword) VALUES (3157, 'tr', 'nas√Ωl')",
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
phpmyfaq/src/phpMyFAQ/Instance/Database/Stopwords.php:3205
"INSERT INTO %sfaqstopwords (id, lang, stopword) VALUES (3171, 'tr', 'onlar√Ωn')",
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
phpmyfaq/translations/language_eu.php:1480
$PMF_LANG['msgIncompatiblePlugins'] = 'Plugin bateraezinак';
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
phpmyfaq/translations/language_sr.php:1313
$PMF_LANG['extractFailure'] = 'Nije moguće raspаkovati preuzeti paket.';
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
phpmyfaq/translations/language_bn.php:341
$PMF_LANG["ad_rs_rating_1"] = "এর র্যাঙ্কিং";
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
phpmyfaq/translations/language_bn.php:347
$PMF_LANG["ad_rs_no"] = "কোন র্যাঙ্কিং উপলব্ধ নেই";
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
phpmyfaq/translations/language_fa.php:27
$PMF_LANG["msgCategory"] = "دستهبندیها";
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
phpmyfaq/translations/language_fa.php:28
$PMF_LANG["msgShowAllCategories"] = "همه دستهبندیها";
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
phpmyfaq/translations/language_fa.php:32
$PMF_LANG["msgOpenQuestions"] = "پرسشهای باز";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
phpmyfaq/admin/assets/src/group/groups.test.ts:83
data-msg-saved="Language restrictions saved." data-csrf-token="csrf-language-restrictions"></div>
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/fixtures/oauth2/private.key:1
-----BEGIN PRIVATE KEY-----
LOWInventory / provenance · inv.hidden_file · CWE-1104
.browserslistrc
.browserslistrc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose

Gates applied: no_behavioural_pass.

Audited 2026-09-28 · audit v0.4.1 · source sha 9ca9c1255fa4full audit observations/trust-audit/mcp-server/thorsten__phpmyfaq.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-289ca9c1255fa4BLOCKF42first audit
06

Questions

What is the PhpMyFAQ MCP server?

phpMyFAQ - Open Source FAQ web application for PHP 8.4+ and MySQL, PostgreSQL and other databases

What tools does PhpMyFAQ expose?

17 in total: 16 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is PhpMyFAQ safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (42/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does PhpMyFAQ need?

It reads E2E_ADMIN_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (9ca9c1255fa4), read on 2026-09-28. The repository is watched and re-audited when it changes.

Advertisement