
Automatic Submenu for Categories & Pages Security & Risk Analysis
wordpress.org/plugins/automatic-submenuAutomatically append children posts and pages as submenu items in the frontend
Is Automatic Submenu for Categories & Pages Safe to Use in 2026?
Generally Safe
Score 85/100Automatic Submenu for Categories & Pages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "automatic-submenu" plugin v1.0.0 demonstrates a generally good security posture with a very limited attack surface, as indicated by zero AJAX handlers, REST API routes, shortcodes, and cron events. The plugin also adheres to secure coding practices by exclusively using prepared statements for its single SQL query and avoids file operations and external HTTP requests. However, a significant concern arises from the output escaping analysis, where only 44% of outputs are properly escaped. This leaves a substantial portion of dynamic content vulnerable to Cross-Site Scripting (XSS) attacks if user-supplied data is included in these unescaped outputs.
The taint analysis reveals two flows with unsanitized paths. While these are not classified as critical or high severity in this specific analysis, the presence of unsanitized paths is a red flag and warrants further investigation. The complete lack of vulnerability history is a positive sign, suggesting the plugin has historically been maintained securely or has not been a target. However, it's important to remember that this is based on past performance and doesn't guarantee future security. In conclusion, the plugin's minimal attack surface and use of prepared statements are strengths, but the high percentage of unescaped output and the identified unsanitized paths represent notable risks that need to be addressed.
Key Concerns
- High percentage of improperly escaped output
- Unsanitized paths found in taint analysis
- Lack of capability checks on entry points
- Lack of nonce checks on entry points
Automatic Submenu for Categories & Pages Security Vulnerabilities
Automatic Submenu for Categories & Pages Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Automatic Submenu for Categories & Pages Attack Surface
WordPress Hooks 7
Maintenance & Trust
Automatic Submenu for Categories & Pages Maintenance & Trust
Maintenance Signals
Community Trust
Automatic Submenu for Categories & Pages Alternatives
Auto Submenu
auto-submenu
Dynamic menus: Add a page to your menu and then let WordPress automatically add the child pages.
Simple Menu Order Column
simple-menu-order-column
Expose menu order column on your dashboard listings.
SF Category Menu
sf-category-menu
Easy treeview menu for WordPress categories.
Express Posts
express-posts
Express posts provides a widget to display either a subset of posts, the children of a page or its siblings.
Menu to Page Display
menu-to-page-display
Display a menu within a page using the [menu-display] shortcode.
Automatic Submenu for Categories & Pages Developer Profile
1 plugin · 10 total installs
How We Detect Automatic Submenu for Categories & Pages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/automatic-submenu/assets/script.jsassets/script.jsHTML / DOM Fingerprints
field-automatic-maxfield-automatic-orderhidden-fieldname="menu-item-automaticname="menu-item-automatic-maxname="menu-item-automatic-orderid="edit-menu-item-automatic-id="edit-menu-item-automatic-max-id="edit-menu-item-automatic-order-automaticsubmenu_children_order