• The UFAQs plugin is generating a persistent admin notice pitching the unrelated AI Admin Assistance plugin. The notice is dismissable, but it comes back every time you login. This is confusing for my users who don’t understand what it is. Can you please modify this behavior to offer the option to dismiss the notice forever?

Viewing 10 replies - 1 through 10 (of 10 total)
  • Plugin Support jaysupport

    (@jaysupport)

    Hi Liz,

    Thanks for reporting this to us. It should definitely go away and not come back when you click on that X.

    I just tested and, with the latest version of the plugin, it is being correctly dismissed. So I wonder if there’s some issue going on here that is specific to your site.

    Can you send me a screenshot of where you are seeing it?

    Can you open the developer console in your browser (https://balsamiq.com/support/faqs/browser-console/), after you click the X to dismiss the notice, and let me know if it shows any errors there related to the notice?

    I second Elizabeth’s issue. It wasn’t obvious either what plugin was creating these promotional AI Assistant notices, I had to hunt down the common developers to find it was UFAQ.

    I just disabled the notice on the Dashboard and checked my Developer Console:

    Failed to load resource: net::ERR_BLOCKED_BY_CLIENT from https://stats.wp.com/w.js?ver=202618 was the only error present.

    Plugin Support jaysupport

    (@jaysupport)

    Hi Soprano,

    I apologize for any issues with this.

    First off, I just wanted to clarify that the notice is designed to stay away. We did not intentionally make it so that it constantly comes back even if you dismiss it. That seems to be some kind of issue specific to your sites. Also, the plugin it showcases is not unrelated. We programmed a bunch of new in-admin extra help and guidance for the Ultimate FAQ plugin directly via that admin assistance plugin. We’re not just hawking a new plugin we want you to use. It will actually greatly help (especially new) users of the FAQ plugin get started without needing to sift through the documentation or wait for answers from support. That being said, the messaging about this was not clear, and I’ve already advised the development team of this, so hopefully we can make it more obvious what the link is between the two plugins.

    Are you saying that, like Liz, even if you dismiss the notice, it comes right back, or comes back shortly thereafter?

    Do you happen to have more than one of our plugins installed?

    It’s frustrating to have this kind of notice pop up that doesn’t appear to identify itself. There’s no branding or name involved, just links. That combined with my reason for being in the admin today is especially annoying… it turns out that either a plugin update or a bug in the plugin allowed many of the websites I manage to get malware injected in a “font” file in the plugin’s folder. So I’ve been having to clean that out and generally check other files, etc. My first thought was that this notice in the admin was caused by the malware, to get people to click a link. Nothing at https://www.wpaiplugins.dev either.

    Thread Starter Elizabeth Eisworth (Liz)

    (@sangfroidliz)

    Hi! I’m not seeing the persistent behavior now. I’m not sure why, but it does appear to be staying dismissed for me now. ¯_(ツ)_/¯

    Plugin Support jaysupport

    (@jaysupport)

    @sangfroidliz Glad to hear that. Thank you for confirming. Sorry again for the confusion.

    @mywebmaestro There has been no bug or issue with the plugin that should have allowed malware in like you say. Would you be able to tell me which exact file it is? And is this still active or have you removed/taken care of the issue?

    During user scan [id#] started on Sun May 3 08:56:19 EDT 2026 finished on Sun May 3 09:02:06 EDT 2026 were scanned 25583 files 1 malware was detected: /home/[accountname]/public_html/wp-content/plugins/ultimate-faqs/lib/FPDF/font/courierb.php

    The file was getting emptied by the malware scanning software, but I’ve been removing it altogether and then replacing core WordPress files as a precaution, etc.

    Plugin Support jaysupport

    (@jaysupport)

    Ok, thank you for confirming that. By chance, did you contact us via email about this same issue (the malware in the font file)? We received another report via email of this exact issue, and it would be strange that malware injected by a source outside our plugin targeted the exact same font file in our plugin for two different users.

    I hadn’t sent a report in I don’t think, but I had the same exact problem on about 10 different websites that were unrelated to each other aside from having the faq plugin installed on them.

    Plugin Support jaysupport

    (@jaysupport)

    Thanks for getting back to me. Just to be clear, that file itself is supposed to just contain info about the Courier font used by the FPDF library, which we use to be able to export your FAQs to a PDF file. That file itself should not be able to be an entry point for malware like you are describing. However, it’s possible that, if you have malware that is targeting files, it is updating or replacing that specific file.

    If you delete the Ultimate FAQ plugin (you will not lose any of your data, FAQs, settings, etc.) and install it fresh, and then immediately run another scan, does that file still get flagged?

Viewing 10 replies - 1 through 10 (of 10 total)

You must be logged in to reply to this topic.