
Animated AL List Security & Risk Analysis
wordpress.org/plugins/animated-al-listIt helps you to create beautiful dynamic menu(link list/text information/images/icons).It will revive your site and let users look at your page anew.
Is Animated AL List Safe to Use in 2026?
Use With Caution
Score 64/100Animated AL List has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'animated-al-list' plugin version 1.0.6 exhibits a mixed security posture. On the positive side, the static analysis shows no critical or high severity taint flows, a good percentage of SQL queries using prepared statements, and a reasonable level of output escaping. The presence of nonce and capability checks on most entry points is also encouraging. However, the plugin's history reveals a known medium severity vulnerability for Cross-Site Scripting (XSS) that remains unpatched, which is a significant concern. While the code analysis itself doesn't highlight immediate critical risks, the historical vulnerability suggests potential weaknesses in how user input is handled, particularly in older or less frequently reviewed code sections. The single shortcode represents the primary attack surface, and while it currently has no explicit auth checks, the absence of taint flows suggests this might not be an immediate exploitable risk, but warrants further investigation if the shortcode processes user-provided data.
The overall security picture is one of a plugin with some good security practices in place but a lingering, unaddressed vulnerability. The unpatched XSS is the most pressing issue. While the current code analysis doesn't flag it directly, it strongly implies that the plugin's input sanitization and output escaping might not be universally robust, especially concerning the specific vector exploited in the past. The absence of dangerous functions and external HTTP requests is a strength, but the plugin's security cannot be considered strong until the known XSS vulnerability is resolved.
Key Concerns
- Unpatched medium severity CVE
Animated AL List Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Animated AL List <= 1.0.6 - Reflected Cross-Site Scripting
Animated AL List Code Analysis
SQL Query Safety
Output Escaping
Animated AL List Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Animated AL List Maintenance & Trust
Maintenance Signals
Community Trust
Animated AL List Alternatives
Easy Sidebar Menu Widget
easy-sidebar-menu-widget
Add WordPress Dropdown Menu Widget easily! Upgrade your sidebar menus to responsive dropdown widget now!
Sidebar Menu Widget
sidebar-menu-widget
Easily add a sidebar menu to your widgetable sidebar. With this plugin you can create a sidebar menu.
Custom Page Menus
custom-page-menus
Custom Page Menus plugin allows custom menus to be defined on a per-page basis.
BuddyMenu BuddyLinks
buddymenu-buddylinks
BuddyPress BuddyLinks does three things really well:
DMG Custom Menu Widget
dmg-custom-menu-widget
Display any Menu in your sidebar or widgetized area. With advanced options to add CSS classes, modify the title & add custom HTML/ Text.
Animated AL List Developer Profile
1 plugin · 10 total installs
How We Detect Animated AL List
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/animated-al-list/css/jquery-ui.css/wp-content/plugins/animated-al-list/css/main.css/wp-content/plugins/animated-al-list/css/jquery.minicolors.css/wp-content/plugins/animated-al-list/js/upload_media_bg_files.js/wp-content/plugins/animated-al-list/js/jquery.minicolors.min.jsanimated-al-list/css/jquery-ui.css?ver=animated-al-list/css/main.css?ver=animated-al-list/css/jquery.minicolors.css?ver=animated-al-list/js/upload_media_bg_files.js?ver=animated-al-list/js/jquery.minicolors.min.js?ver=HTML / DOM Fingerprints
animated_al_list_containermain_element[animated_al_list]