Clean WP Admin Menu Security & Risk Analysis

wordpress.org/plugins/clean-wp-admin-menu

You can make rarely used items in the admin menu hidden.

600 active installs v1.0.1 PHP + WP 4.0+ Updated Jun 21, 2016
admindashboarddesigninterfacemenu
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Clean WP Admin Menu Safe to Use in 2026?

Generally Safe

Score 85/100

Clean WP Admin Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The 'clean-wp-admin-menu' plugin version 1.0.1 exhibits a generally positive security posture based on the static analysis. The plugin has no known vulnerabilities, no critical or high-severity issues in its history, and a very small attack surface. Crucially, it utilizes prepared statements for all its SQL queries, which is a strong indicator of secure database interaction. The presence of a nonce check also suggests some awareness of basic WordPress security mechanisms. However, the analysis reveals a concerning weakness in output escaping, with only 20% of outputs being properly escaped. This could leave the plugin susceptible to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully before being displayed. Additionally, the complete lack of capability checks for any entry points, while the attack surface is currently zero, is a potential future risk if functionality were to be added without proper authorization checks. The plugin's vulnerability history is spotless, which is a significant strength, but this is offset by the identified output escaping issues. Overall, while the plugin is currently clean and follows some good practices, the unescaped output represents a notable security concern that requires attention.

Key Concerns

  • Output escaping is only 20% proper
  • No capability checks on entry points
Vulnerabilities
None known

Clean WP Admin Menu Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Clean WP Admin Menu Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
2 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

20% escaped10 total outputs
Attack Surface

Clean WP Admin Menu Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionplugins_loadedincludes\class-clean-wp-admin-menu.php:135
actionadmin_enqueue_scriptsincludes\class-clean-wp-admin-menu.php:150
actionadmin_enqueue_scriptsincludes\class-clean-wp-admin-menu.php:151
actionadmin_menuincludes\class-clean-wp-admin-menu.php:154
actionadmin_menuincludes\class-clean-wp-admin-menu.php:157
Maintenance & Trust

Clean WP Admin Menu Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedJun 21, 2016
PHP min version
Downloads9K

Community Trust

Rating98/100
Number of ratings17
Active installs600
Developer Profile

Clean WP Admin Menu Developer Profile

borantula

2 plugins · 700 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Clean WP Admin Menu

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/clean-wp-admin-menu/admin/css/clean-wp-admin-menu-admin.css/wp-content/plugins/clean-wp-admin-menu/admin/js/clean-wp-admin-menu-admin.js
Script Paths
admin/js/clean-wp-admin-menu-admin.js
Version Parameters
clean-wp-admin-menu/admin/css/clean-wp-admin-menu-admin.css?ver=clean-wp-admin-menu/admin/js/clean-wp-admin-menu-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
clean-wp-menu__valid-item
FAQ

Frequently Asked Questions about Clean WP Admin Menu