
Auto Submenu Security & Risk Analysis
wordpress.org/plugins/auto-submenuDynamic menus: Add a page to your menu and then let WordPress automatically add the child pages.
Is Auto Submenu Safe to Use in 2026?
Generally Safe
Score 100/100Auto Submenu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "auto-submenu" v1.0.5 plugin exhibits a strong security posture based on the static analysis provided. The absence of any identified dangerous functions, SQL queries not utilizing prepared statements, and properly escaped output are all positive indicators. The plugin also demonstrates a lack of file operations and external HTTP requests, further reducing its attack surface. Furthermore, the complete absence of known vulnerabilities (CVEs) in its history suggests a commitment to security or a lack of historical targeting.
However, the static analysis reveals a significant lack of security controls for its entry points. With zero AJAX handlers, REST API routes, shortcodes, or cron events, the plugin has no discernable attack surface. Crucially, none of these potential entry points have any authentication or capability checks. While this might be due to the plugin's intended functionality, it means that any potential future addition of such features would immediately pose a security risk if not properly secured.
In conclusion, the plugin is currently very secure due to its minimal functionality and absence of known vulnerabilities. The core code appears to follow secure coding practices. The primary concern lies in the complete absence of any protective measures for its non-existent entry points, which, while not a current risk, represents a potential area for future vulnerability if the plugin's scope expands without implementing proper security checks.
Key Concerns
- No capability checks on potential entry points
- No nonce checks on potential entry points
Auto Submenu Security Vulnerabilities
Auto Submenu Code Analysis
Output Escaping
Auto Submenu Attack Surface
WordPress Hooks 6
Maintenance & Trust
Auto Submenu Maintenance & Trust
Maintenance Signals
Community Trust
Auto Submenu Alternatives
Exclude Pages
exclude-pages
This plugin adds a checkbox, “include this page in menus”, uncheck this to exclude pages from the page navigation that users see on your site.
CC Child Pages
cc-child-pages
Display WordPress child pages in a responsive grid or list using a shortcode, Gutenberg block or Elementor widget.
Exclude Pages From Menu
exclude-pages-from-menu
The plugin provides option in the page edit screen to remove page from navigation menu in the front end of site.
Collapsing Pages
collapsing-pages
This plugin uses Javascript to dynamically expand or collapsable the set of pages for each parent page.
Codepress Menu
codepress-menu
Allows you to display a sub-menu, it's depth from there on and gives you control over the menu-item classes.
Auto Submenu Developer Profile
3 plugins · 4K total installs
How We Detect Auto Submenu
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/auto-submenu/src/blocks/asm_core_navigation_link/build/index.js/wp-content/plugins/auto-submenu/src/blocks/asm_core_navigation_link/build/index.jsauto-submenu/src/blocks/asm_core_navigation_link/build/index.js?ver=HTML / DOM Fingerprints
asm_unfoldasm_item_depthASM_Manager_Free