Animated AL List Security & Risk Analysis

wordpress.org/plugins/animated-al-list

It helps you to create beautiful dynamic menu(link list/text information/images/icons).It will revive your site and let users look at your page anew.

10 active installs v1.0.6 PHP + WP 3.6+ Updated Nov 4, 2015
jquery-menumenumenu-widgetplugin-for-menuwordpress-dynamic-menu
64
C · Use Caution
CVEs total1
Unpatched1
Last CVEJun 7, 2024
Download
Safety Verdict

Is Animated AL List Safe to Use in 2026?

Use With Caution

Score 64/100

Animated AL List has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Jun 7, 2024Updated 10yr ago
Risk Assessment

The 'animated-al-list' plugin version 1.0.6 exhibits a mixed security posture. On the positive side, the static analysis shows no critical or high severity taint flows, a good percentage of SQL queries using prepared statements, and a reasonable level of output escaping. The presence of nonce and capability checks on most entry points is also encouraging. However, the plugin's history reveals a known medium severity vulnerability for Cross-Site Scripting (XSS) that remains unpatched, which is a significant concern. While the code analysis itself doesn't highlight immediate critical risks, the historical vulnerability suggests potential weaknesses in how user input is handled, particularly in older or less frequently reviewed code sections. The single shortcode represents the primary attack surface, and while it currently has no explicit auth checks, the absence of taint flows suggests this might not be an immediate exploitable risk, but warrants further investigation if the shortcode processes user-provided data.

The overall security picture is one of a plugin with some good security practices in place but a lingering, unaddressed vulnerability. The unpatched XSS is the most pressing issue. While the current code analysis doesn't flag it directly, it strongly implies that the plugin's input sanitization and output escaping might not be universally robust, especially concerning the specific vector exploited in the past. The absence of dangerous functions and external HTTP requests is a strength, but the plugin's security cannot be considered strong until the known XSS vulnerability is resolved.

Key Concerns

  • Unpatched medium severity CVE
Vulnerabilities
1

Animated AL List Security Vulnerabilities

CVEs by Year

1 CVE in 2024 · unpatched
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-5728medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Animated AL List <= 1.0.6 - Reflected Cross-Site Scripting

Jun 7, 2024Unpatched
Code Analysis
Analyzed Mar 17, 2026

Animated AL List Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
17 prepared
Unescaped Output
13
41 escaped
Nonce Checks
2
Capability Checks
7
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

94% prepared18 total queries

Output Escaping

76% escaped54 total outputs
Attack Surface

Animated AL List Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[animated_al_list] animated-al-list.php:45
WordPress Hooks 6
actioninitadmin_animated_al_list.php:18
actionwidgets_initadmin_animated_al_list.php:19
actioninitinc\actions_front.php:7
actionwp_footerinc\actions_front.php:8
actionwidgets_initinc\actions_front.php:12
actionadmin_menuinc\admincommon.class.php:58
Maintenance & Trust

Animated AL List Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedNov 4, 2015
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Animated AL List Developer Profile

alexdtn

1 plugin · 10 total installs

69
trust score
Avg Security Score
64/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Animated AL List

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/animated-al-list/css/jquery-ui.css/wp-content/plugins/animated-al-list/css/main.css/wp-content/plugins/animated-al-list/css/jquery.minicolors.css/wp-content/plugins/animated-al-list/js/upload_media_bg_files.js/wp-content/plugins/animated-al-list/js/jquery.minicolors.min.js
Version Parameters
animated-al-list/css/jquery-ui.css?ver=animated-al-list/css/main.css?ver=animated-al-list/css/jquery.minicolors.css?ver=animated-al-list/js/upload_media_bg_files.js?ver=animated-al-list/js/jquery.minicolors.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
animated_al_list_containermain_element
Shortcode Output
[animated_al_list]
FAQ

Frequently Asked Questions about Animated AL List