
Advance Nav Menu Manager Security & Risk Analysis
wordpress.org/plugins/advance-nav-menu-managerAdvance Nav Menu Manager lets WordPress admins move, copy, duplicate, or disable menu items with advanced controls directly in the admin panel.
Is Advance Nav Menu Manager Safe to Use in 2026?
Generally Safe
Score 100/100Advance Nav Menu Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'advance-nav-menu-manager' plugin v1.3 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, external HTTP requests, and the consistent use of prepared statements for SQL queries are positive indicators. Furthermore, the high percentage of properly escaped output and the presence of a nonce check suggest good development practices for protecting against common web vulnerabilities. The plugin also has no recorded vulnerability history, which is a significant strength.
Despite these positive aspects, the static analysis reveals a minor concern regarding capability checks. While the plugin has a small attack surface with only two AJAX handlers, and both appear to be protected by authentication, the lack of explicit capability checks on these AJAX handlers could represent a potential weakness. This means that while an attacker would need to be authenticated to reach these endpoints, they might not be restricted based on user roles or specific permissions, potentially leading to unintended actions if not handled carefully within the AJAX handler logic itself. The absence of taint analysis data is a neutral observation, meaning no flaws were detected in that specific area during the analysis.
In conclusion, the 'advance-nav-menu-manager' plugin demonstrates a generally secure design with robust input handling and no historical vulnerabilities. The primary area for improvement lies in ensuring explicit capability checks are implemented for its AJAX endpoints to further harden its security against privilege escalation or unauthorized actions within authenticated user contexts. Overall, the plugin appears to be a low-risk option for users.
Key Concerns
- Missing capability checks on AJAX handlers
Advance Nav Menu Manager Security Vulnerabilities
Advance Nav Menu Manager Release Timeline
Advance Nav Menu Manager Code Analysis
Output Escaping
Advance Nav Menu Manager Attack Surface
AJAX Handlers 2
WordPress Hooks 3
Maintenance & Trust
Advance Nav Menu Manager Maintenance & Trust
Maintenance Signals
Community Trust
Advance Nav Menu Manager Alternatives
CC Duplicate Menu
cc-duplicate-menu
Safely duplicate WordPress navigation menus from the menu editor.
Exclude Pages From Menu
exclude-pages-from-menu
The plugin provides option in the page edit screen to remove page from navigation menu in the front end of site.
Remove admin menus by role
remove-admin-menus-by-role
Select easily which admin menus to remove for which roles.
Menu Item Duplicator
menu-item-duplicator
Allow you to duplicate menu items and their sub-elements in Appearance > Menus
Auto Subpage Menu
auto-subpage-menu
By default wordpress menu system, wordpress can only automatically add/remove top-level page to/from menus
Advance Nav Menu Manager Developer Profile
14 plugins · 17K total installs
How We Detect Advance Nav Menu Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advance-nav-menu-manager/assets/js/advance-navmenu-manager.jsHTML / DOM Fingerprints
field-custom_menu_metalogged-input-holderhave_sub_item-buttonhave_sub_item-button-labelanmm-duplicate-submit<!-- New interface option for user -->name="nav_menu_id_advance_item"id="nav_menu_id_advance_itemname="current_menu_id"id="current_menu_idname="menu_move_select"id="menu_move_select+6 moreANM_AJAX_OB