PhpMyFAQBLOCK
phpMyFAQ - Open Source FAQ web application for PHP 8.4+ and MySQL, PostgreSQL and other databases
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://phpmyfaq.readthedocs.io/en/latest/?badge=latest)
What is phpMyFAQ?
phpMyFAQ is a multilingual, AI-ready, and scalable FAQ platform built for modern knowledge management. Powered by PHP 8.4+ and a fully database-driven architecture, it delivers fast search with Elasticsearch/OpenSearch, flexible multi-user permissions, and a powerful content management system with revision history and WYSIWYG editing.
With 40+ languages, responsive Twig-based templates, a REST API, 2FA security, enterprise authentication (LDAP, Active Directory, Entra ID), and a built-in plugin system, phpMyFAQ integrates seamlessly into almost any environment.
Deploy it on traditional hosting or run it in the cloud via Docker.
Requirements
phpMyFAQ requires PHP 8.4 or higher and a supported database system. Supported databases include MySQL, MariaDB, Percona Server, PostgreSQL, Microsoft SQL Server, and SQLite3.
For enhanced search capabilities using Elasticsearch or OpenSearch, Elasticsearch 8.x or later or OpenSearch 2.x or later is required.
For a complete and up-to-date list of system requirements, please refer to the official documentation at phpmyfaq.de.
Installation
phpMyFAQ installation package for end-users
The best way to install phpMyFAQ is to download it on phpmyfaq.de, unzip the package, and open http://www.example.org/phpmyfaq/setup/ in your preferred browser.
phpMyFAQ installation with Docker
Production images
Every release is published to the GitHub Container Registry as ghcr.io/thorsten/phpmyfaq: (Apach
9ca9c1255fa4OBSERVED · 2026-09-28Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add phpmyfaq --env E2E_ADMIN_PASSWORD=${E2E_ADMIN_PASSWORD} -- npx -y @thorsten/[email protected]{
"mcpServers": {
"phpmyfaq": {
"command": "npx",
"args": [
"-y",
"@thorsten/[email protected]"
],
"env": {
"E2E_ADMIN_PASSWORD": "${E2E_ADMIN_PASSWORD}"
}
}
}
}Exposed tools (17)
16 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Admins | read | Admin group |
Editors | read | Editorial team |
categoryId | read | The category ID. |
faqId | read | The FAQ record ID. |
faq_search | read | Search through the phpMyFAQ knowledge base to find relevant FAQ entries that can answer questions. |
limit | read | Alternative to per_page for offset-based pagination |
minimal_tool | read | Minimal tool |
offset | read | Offset for pagination (overrides page parameter) |
order | write | Sort order |
page | read | Page number for pagination (1-indexed) |
per_page | read | Number of items per page |
q | read | The search term |
sort | read | Field to sort by |
tagId | read | The tag ID. |
test_tool | read | A test tool |
tool | read | desc |
type | read | The backup type. Can be |
Trust audit
BLOCKgrade F · trust 42/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (10 observation(s))
- Network
- declared (7 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
$results = $redis->exec();
"IF NOT EXISTS (SELECT * FROM sys.schemas WHERE name = '%s') EXEC('CREATE SCHEMA %s')","IF NOT EXISTS (SELECT * FROM sys.schemas WHERE name = '%s') EXEC('CREATE SCHEMA %s')","IF NOT EXISTS (SELECT * FROM sys.schemas WHERE name = '%s') EXEC('CREATE SCHEMA [%s]')",. "EXEC('ALTER TABLE %s DROP CONSTRAINT ' + @constraintName)",dejavumathtexgyre.ctg.z
dejavumathtexgyre.z
dejavusans.ctg.z
dejavusans.z
dejavusansb.ctg.z
OPENSEARCH_BASE_URI=http://127.0.0.1:9201
ELASTICSEARCH_BASE_URI=http://127.0.0.1:9200
"INSERT INTO %sfaqstopwords (id, lang, stopword) VALUES (3151, 'tr', 'k√Ωrk')",
"INSERT INTO %sfaqstopwords (id, lang, stopword) VALUES (3157, 'tr', 'nas√Ωl')",
"INSERT INTO %sfaqstopwords (id, lang, stopword) VALUES (3171, 'tr', 'onlar√Ωn')",
$PMF_LANG['msgIncompatiblePlugins'] = 'Plugin bateraezinак';
$PMF_LANG['extractFailure'] = 'Nije moguće raspаkovati preuzeti paket.';
$PMF_LANG["ad_rs_rating_1"] = "এর র্যাঙ্কিং";
$PMF_LANG["ad_rs_no"] = "কোন র্যাঙ্কিং উপলব্ধ নেই";
$PMF_LANG["msgCategory"] = "دستهبندیها";
$PMF_LANG["msgShowAllCategories"] = "همه دستهبندیها";
$PMF_LANG["msgOpenQuestions"] = "پرسشهای باز";
data-msg-saved="Language restrictions saved." data-csrf-token="csrf-language-restrictions"></div>
-----BEGIN PRIVATE KEY-----
.browserslistrc
Gates applied: no_behavioural_pass.
9ca9c1255fa4full audit observations/trust-audit/mcp-server/thorsten__phpmyfaq.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-28 | 9ca9c1255fa4 | BLOCK | F | 42 | first audit |
Questions
What is the PhpMyFAQ MCP server?
phpMyFAQ - Open Source FAQ web application for PHP 8.4+ and MySQL, PostgreSQL and other databases
What tools does PhpMyFAQ expose?
17 in total: 16 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is PhpMyFAQ safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (42/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does PhpMyFAQ need?
It reads E2E_ADMIN_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (9ca9c1255fa4), read on 2026-09-28. The repository is watched and re-audited when it changes.