Alligator Menu Popup Security & Risk Analysis

wordpress.org/plugins/alligator-menu-popup

Add the 'mpopup' class to a menu item in a custom menu to open the target in a popup Window.

600 active installs v2.0.0 PHP + WP 4.9+ Updated Jun 23, 2025
popuppopup-windowpopupsshortcodesimple
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Alligator Menu Popup Safe to Use in 2026?

Generally Safe

Score 100/100

Alligator Menu Popup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The "alligator-menu-popup" v2.0.0 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code analysis reveals good development practices, including the complete use of prepared statements for SQL queries, proper output escaping for all identified outputs, and the presence of capability checks. The lack of dangerous functions, file operations, and external HTTP requests further enhances its security. The complete absence of vulnerability history and taint analysis issues indicates a mature and well-maintained codebase.

While the plugin appears robust, the complete lack of any identified entry points, including AJAX handlers or REST API routes, is unusual and could be an anomaly in the analysis or reflect a very simplistic plugin functionality. The absence of nonce checks, though not explicitly flagged as a concern due to the lack of handlers, is typically a critical security measure for interactive elements. However, given the overall clean report and zero historical vulnerabilities, the current version of "alligator-menu-popup" appears to be very secure. The primary strength lies in its minimal attack surface and adherence to secure coding practices where code does exist.

Vulnerabilities
None known

Alligator Menu Popup Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Alligator Menu Popup Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
7 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped7 total outputs
Attack Surface

Alligator Menu Popup Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_enqueue_scriptsadmin.php:31
actionadmin_menuadmin.php:39
actionadmin_initadmin.php:40
filterplugin_row_metaalligator-menu-popup.php:44
actionwp_enqueue_scriptsalligator-menu-popup.php:88
Maintenance & Trust

Alligator Menu Popup Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 23, 2025
PHP min version
Downloads21K

Community Trust

Rating96/100
Number of ratings17
Active installs600
Developer Profile

Alligator Menu Popup Developer Profile

cubecolour

17 plugins · 21K total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Alligator Menu Popup

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/alligator-menu-popup/css/admin.css/wp-content/plugins/alligator-menu-popup/js/mpopup.js
Script Paths
/wp-content/plugins/alligator-menu-popup/js/mpopup.js
Version Parameters
alligator-menu-popup/css/admin.css?ver=alligator-menu-popup/js/mpopup.js?ver=

HTML / DOM Fingerprints

CSS Classes
mpopupmpopup-wrappermpopup-options
HTML Comments
Package: Alligator Menu Popup plugin for WordPressAuthor: cubecolourVersion: 2.0.0File: Admin Panel+7 more
Data Attributes
id="mpopup"name="cc_mpopup_width"name="cc_mpopup_height"name="cc_mpopup_scroll"
JS Globals
mPopupParams
FAQ

Frequently Asked Questions about Alligator Menu Popup