Admin Menu Customizer Security & Risk Analysis

wordpress.org/plugins/admin-menu-customizer

Customize the order of the admin menu and optionally change menu item titles or hide some items.

10 active installs v1.1.4 PHP 5.6+ WP 4.6+ Updated Dec 8, 2022
admin-menucustom-menuhide-menumenumenu-order
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Admin Menu Customizer Safe to Use in 2026?

Generally Safe

Score 85/100

Admin Menu Customizer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The admin-menu-customizer plugin, version 1.1.4, exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points, coupled with the complete lack of dangerous function usage and the use of prepared statements for all SQL queries, are positive indicators. The code also demonstrates a high level of output escaping, with 98% of outputs being properly escaped, and no file operations or external HTTP requests being made. The plugin's vulnerability history is also clean, with zero known CVEs and no recorded historical vulnerabilities, suggesting a consistent focus on security by the developers.

While the static analysis reveals a very secure codebase, the only potential concern arises from the complete absence of nonce checks and capability checks. Although the current attack surface is zero, this could become a concern if the plugin were to introduce any new entry points in the future without implementing these essential security measures. However, given the current state, this is a minor concern rather than an immediate threat. The overall security of admin-menu-customizer v1.1.4 appears to be excellent, with developers demonstrating good practices in code security and a commitment to maintaining a vulnerability-free plugin.

Key Concerns

  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

Admin Menu Customizer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Admin Menu Customizer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
42 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

98% escaped43 total outputs
Attack Surface

Admin Menu Customizer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionadmin_menubootstrap.php:44
actionadmin_initbootstrap.php:50
actionadmin_enqueue_scriptsbootstrap.php:53
filteradmin_footer_textbootstrap.php:59
actionadmin_noticesbootstrap.php:62
actionall_admin_noticesbootstrap.php:63
filtercustom_menu_orderbootstrap.php:73
filtermenu_orderbootstrap.php:74
actionadmin_menubootstrap.php:77
actionadmin_menubootstrap.php:80
actionadmin_menubootstrap.php:81
Maintenance & Trust

Admin Menu Customizer Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedDec 8, 2022
PHP min version5.6
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Admin Menu Customizer Developer Profile

Bowo

7 plugins · 211K total installs

80
trust score
Avg Security Score
89/100
Avg Patch Time
35 days
View full developer profile
Detection Fingerprints

How We Detect Admin Menu Customizer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/admin-menu-customizer/assets/css/admin-menu-customizer.css/wp-content/plugins/admin-menu-customizer/assets/js/admin-menu-customizer.js/wp-content/plugins/admin-menu-customizer/assets/js/jquery.jsticky.mod.min.js
Script Paths
/wp-content/plugins/admin-menu-customizer/assets/js/admin-menu-customizer.js/wp-content/plugins/admin-menu-customizer/assets/js/jquery.jsticky.mod.min.js
Version Parameters
admin-menu-customizer/assets/css/admin-menu-customizer.css?ver=admin-menu-customizer/assets/js/admin-menu-customizer.js?ver=admin-menu-customizer/assets/js/jquery.jsticky.mod.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
amcustamcust-headeramcust-header-leftamcust-headingamcust-header-actionamcust-header-rightamcust-save-buttonamcust-changes-saved+3 more
HTML Comments
Hide to prevent flash of fields appearing at the bottom of the pageInfoReviewFeedback+1 more
Data Attributes
data-amcust-iddata-amcust-typedata-amcust-parentdata-amcust-titledata-amcust-urldata-amcust-icon+1 more
JS Globals
amcust_admin_page
FAQ

Frequently Asked Questions about Admin Menu Customizer