Add To Menus Lite Security & Risk Analysis

wordpress.org/plugins/add-to-menus-lite

Add to Menus provides a quick link in your Wordpress Admin Bar to quickly add a menu item link for the post or page that you are viewing.

10 active installs v0.1 PHP + WP 4.0+ Updated May 21, 2016
adminmenuspostwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Add To Menus Lite Safe to Use in 2026?

Generally Safe

Score 85/100

Add To Menus Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The add-to-menus-lite plugin v0.1 exhibits significant security concerns due to its unprotected entry points. The static analysis reveals two AJAX handlers, both lacking authentication checks, presenting a direct pathway for potential attackers to interact with the plugin's functionality. While the plugin avoids dangerous functions, file operations, and external HTTP requests, this is overshadowed by the critical absence of security measures on its primary interaction points. The limited number of SQL queries and a moderate rate of output escaping are positive indicators, but they do not mitigate the risks introduced by the open AJAX endpoints. The plugin's vulnerability history shows a clean slate, with no recorded CVEs. This could indicate either a lack of focused security auditing on this version or that past development practices were more robust. However, the current analysis of v0.1 suggests that relying solely on the absence of past vulnerabilities is insufficient, given the evident weaknesses in its attack surface. Overall, while the plugin has a low historical vulnerability count, the current static analysis points to a concerning security posture due to unprotected AJAX handlers, demanding immediate attention.

Key Concerns

  • Unprotected AJAX handlers
  • Lack of nonce checks on AJAX handlers
  • Low percentage of properly escaped output
  • Flows with unsanitized paths
Vulnerabilities
None known

Add To Menus Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Add To Menus Lite Release Timeline

v0.1Current
Code Analysis
Analyzed Mar 17, 2026

Add To Menus Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
1 prepared
Unescaped Output
64
40 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

50% prepared2 total queries

Output Escaping

38% escaped104 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
start_el (class.Walker_Nav_Menu_Edit.php:56)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Add To Menus Lite Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_atm_save_menuindex.php:31
authwp_ajax_atm_dismiss_noticeindex.php:33
WordPress Hooks 10
actionadmin_initindex.php:18
actionadmin_bar_menuindex.php:21
actionadmin_noticesindex.php:24
actionadmin_enqueue_scriptsindex.php:27
actionwp_headindex.php:28
filterwp_get_nav_menu_itemsindex.php:37
actionwp_nav_menu_item_custom_fieldsindex.php:41
filterwp_edit_nav_menu_walkerindex.php:44
actionwp_update_nav_menu_itemindex.php:47
actionadd_meta_boxesindex.php:50
Maintenance & Trust

Add To Menus Lite Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedMay 21, 2016
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Add To Menus Lite Developer Profile

Ravi Shakya

3 plugins · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Add To Menus Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/add-to-menus-lite/css/style.css/wp-content/plugins/add-to-menus-lite/js/custom.js/wp-content/plugins/add-to-menus-lite/js/menu.js
Script Paths
/wp-content/plugins/add-to-menus-lite/js/custom.js/wp-content/plugins/add-to-menus-lite/js/menu.js
Version Parameters
add-to-menus-lite/css/style.css?ver=add-to-menus-lite/js/custom.js?ver=add-to-menus-lite/js/menu.js?ver=

HTML / DOM Fingerprints

CSS Classes
atm_admin_baratm_add_to_menus_meta_boxatm-custom-fieldsmenu_access_level_wraprestrict_roles_wrapatm_notice
HTML Comments
<!-- Add To Menus --><!-- Minimum 1 role should be selected --><!-- Add menu to the admin bar --><!-- Add custom css/html -->+22 more
Data Attributes
atm_access_levelatm_menu_roles
JS Globals
atm_access_levelatm_menu_roles
FAQ

Frequently Asked Questions about Add To Menus Lite