
Advanced Menu Manager Pro – Built for Content-heavy WordPress Sites to Add, Filter, Lock, and Edit Menus Easily Security & Risk Analysis
wordpress.org/plugins/advance-menu-managerCreate and manage menus of any size of your content-heavy wordpress blogs and websites. Simplified search and new comprehensive layout.
Is Advanced Menu Manager Pro – Built for Content-heavy WordPress Sites to Add, Filter, Lock, and Edit Menus Easily Safe to Use in 2026?
Generally Safe
Score 96/100Advanced Menu Manager Pro – Built for Content-heavy WordPress Sites to Add, Filter, Lock, and Edit Menus Easily has a strong security track record. Known vulnerabilities have been patched promptly.
The "advance-menu-manager" plugin v3.1.3 presents a mixed security posture. On the positive side, the plugin demonstrates strong practices regarding SQL queries, with 100% using prepared statements, and a high percentage (90%) of output being properly escaped, indicating a focus on preventing common injection and XSS vulnerabilities. The absence of file operations and raw SQL queries is also commendable. However, a significant concern arises from the substantial attack surface, with all 12 identified AJAX handlers lacking authentication checks. This leaves the plugin highly susceptible to unauthorized actions if these handlers are discoverable or predictable by attackers. The vulnerability history, while currently showing no unpatched CVEs, reveals a pattern of past vulnerabilities, particularly missing authorization and CSRF, across various severity levels. This historical data suggests recurring issues with securing entry points, which is further corroborated by the static analysis revealing a lack of authorization checks on all AJAX endpoints.
Key Concerns
- 12 unprotected AJAX handlers
- 5 past high/medium severity vulnerabilities
- Bundled Freemius v1.0 library
Advanced Menu Manager Pro – Built for Content-heavy WordPress Sites to Add, Filter, Lock, and Edit Menus Easily Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Advance Menu Manager <= 3.1.1 - Missing Authorization to Authenticated (Subscriber+) Settings Change
Advance Menu Manager <= 3.0.6 - Missing Authorization
Advance Menu Manager <= 3.0.6 - Cross-Site Request Forgery
Advanced Menu Manager <= 2.9.6 - Cross-Site Request Forgery to Menu Edition
Advanced Menu Manager <= 3.0.6 - Authenticated (Subscriber+) Menu Creation/Deletion
Advanced Menu Manager Pro – Built for Content-heavy WordPress Sites to Add, Filter, Lock, and Edit Menus Easily Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Advanced Menu Manager Pro – Built for Content-heavy WordPress Sites to Add, Filter, Lock, and Edit Menus Easily Attack Surface
AJAX Handlers 12
WordPress Hooks 16
Maintenance & Trust
Advanced Menu Manager Pro – Built for Content-heavy WordPress Sites to Add, Filter, Lock, and Edit Menus Easily Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Menu Manager Pro – Built for Content-heavy WordPress Sites to Add, Filter, Lock, and Edit Menus Easily Alternatives
PublishPress Capabilities – User Role Editor, Access Permissions, User Capabilities, Admin Menus
capability-manager-enhanced
PublishPress Capabilities is the access control plugin. You can manage user capabilities, permissions, user roles, admin menus and more.
User Menus – Nav Menu Visibility
user-menus
Show/hide menu items to logged in users, logged out users or specific user roles. Display logged in user details in menu. Add a logout link to menu.
Nav Menu Roles
nav-menu-roles
Hide custom menu items based on user roles. PLEASE READ THE FAQ IF YOU ARE NOT SEEING THE SETTINGS.
LuckyWP ACF Menu Field
luckywp-acf-menu-field
Add navigation menu field type to Advanced Custom Fields
Admin Tools
admin-tools
Admin Tools Helps you to get better admin for your customers. Manage your menus, plugins, Top Bar, updates and more
Advanced Menu Manager Pro – Built for Content-heavy WordPress Sites to Add, Filter, Lock, and Edit Menus Easily Developer Profile
37 plugins · 95K total installs
How We Detect Advanced Menu Manager Pro – Built for Content-heavy WordPress Sites to Add, Filter, Lock, and Edit Menus Easily
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advance-menu-manager/includes/admin/css/fancy_alert.css/wp-content/plugins/advance-menu-manager/includes/js/fancy_alert.js/wp-content/plugins/advance-menu-manager/includes/js/dsamm_pagination.js/wp-content/plugins/advance-menu-manager/assets/css/amm-styles.css/wp-content/plugins/advance-menu-manager/assets/js/amm-script.js/wp-content/plugins/advance-menu-manager/includes/js/fancy_alert.js/wp-content/plugins/advance-menu-manager/includes/js/dsamm_pagination.js/wp-content/plugins/advance-menu-manager/assets/js/amm-script.jsadvance-menu-manager/includes/admin/css/fancy_alert.css?ver=advance-menu-manager/includes/js/fancy_alert.js?ver=advance-menu-manager/includes/js/dsamm_pagination.js?ver=advance-menu-manager/assets/css/amm-styles.css?ver=advance-menu-manager/assets/js/amm-script.js?ver=HTML / DOM Fingerprints
dsamm-admin-pagemenu-item-amm-descriptionamm-toggle-visibilitydsamm-add-new-menu-itemamm-description-fieldamm-add-menu-item-wrapperprevent direct access data leaksThis is the condition to prevent direct access data leaks.Hook fire on activation of pluginHook for add links on plugin listing+3 moredata-amm-menu-iddata-amm-item-iddata-amm-noncedsamm_data