
BU Navigation Security & Risk Analysis
wordpress.org/plugins/bu-navigationRobust tools for managing hierarchical page content in WordPress. Ideal for blogs with large page counts.
Is BU Navigation Safe to Use in 2026?
Generally Safe
Score 85/100BU Navigation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The bu-navigation plugin v1.3.4 presents a mixed security posture. On the positive side, it has a clean vulnerability history with no recorded CVEs, suggesting a commitment to security or limited exposure to significant vulnerabilities. The plugin also demonstrates good practices in handling SQL queries, with a high percentage using prepared statements, and a reasonable number of capability checks in place.
However, significant concerns arise from the static analysis. The plugin exposes a total of 6 entry points, with 3 of them (all AJAX handlers) lacking authentication checks. This directly creates an attack surface that could be exploited by unauthenticated users. Furthermore, the output escaping is alarmingly low at only 28%, indicating a high likelihood of cross-site scripting (XSS) vulnerabilities. While the taint analysis did not reveal critical or high-severity issues, the presence of 2 flows with unsanitized paths warrants attention, especially in conjunction with the poor output escaping.
In conclusion, while the plugin has no known vulnerabilities and uses prepared statements for SQL, the significant number of unprotected AJAX endpoints and the critically low rate of proper output escaping represent substantial security risks. These weaknesses could be exploited to perform unauthorized actions or execute malicious scripts, despite the absence of a historical vulnerability record.
Key Concerns
- 3 unprotected AJAX handlers
- Low output escaping (28%)
- 2 flows with unsanitized paths
- Only 1 nonce check for 3 unprotected AJAX handlers
BU Navigation Security Vulnerabilities
BU Navigation Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
BU Navigation Attack Surface
AJAX Handlers 3
REST API Routes 2
Shortcodes 1
WordPress Hooks 43
Maintenance & Trust
BU Navigation Maintenance & Trust
Maintenance Signals
Community Trust
BU Navigation Alternatives
Responsive Menu – Create Mobile-Friendly Menu
responsive-menu
Highly customisable Responsive Menu plugin with 150+ options. No coding knowledge needed to design it exactly as you want.
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
PixTypes
pixtypes
A WordPress plugin for managing custom post types and custom meta boxes from a theme.
WebMan Amplifier
webman-amplifier
Amplifies functionality of WP themes. Provides custom post types, shortcodes, metaboxes, icons. Theme developer's best friend!
Bubble Menu – Floating Button Menu with Sticky Navigation
bubble-menu
Create interactive floating bubble menus to enhance site navigation and boost user engagement effortlessly.
BU Navigation Developer Profile
3 plugins · 310 total installs
How We Detect BU Navigation
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bu-navigation/css/bu-navigation.css/wp-content/plugins/bu-navigation/js/bu-navigation.js/wp-content/plugins/bu-navigation/js/bu-navigation.jsbu-navigation/css/bu-navigation.css?ver=bu-navigation/js/bu-navigation.js?ver=HTML / DOM Fingerprints
bu-navigation-widgetbu-navigation-manager-wrapdata-bu-nav-idbu_navigation_widget_id