
CMS Navigation Security & Risk Analysis
wordpress.org/plugins/cms-navigationOut-of-the-box support for full CMS navigation in your WordPress site including drop down menus, breadcrumbs trail and sidebar navigation.
Is CMS Navigation Safe to Use in 2026?
Generally Safe
Score 85/100CMS Navigation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cms-navigation" plugin v1.4.2 presents a mixed security posture. While the attack surface appears to be zero and there are no recorded vulnerabilities (CVEs), the static analysis reveals significant concerns regarding data handling. Specifically, 100% of SQL queries are not using prepared statements, indicating a high risk of SQL injection vulnerabilities. Furthermore, a very low percentage of output is properly escaped, suggesting potential cross-site scripting (XSS) issues. The taint analysis, though limited, identified two flows with unsanitized paths, which could lead to further vulnerabilities if not addressed. The complete absence of capability checks and nonce checks on potential entry points (even though reported as zero) combined with raw SQL and unescaped output creates a worrying combination of weaknesses. In conclusion, while the lack of historical vulnerabilities is a positive sign, the static analysis highlights critical areas for immediate improvement to secure this plugin.
Key Concerns
- 100% of SQL queries lack prepared statements
- Only 5% of outputs are properly escaped
- 2 taint flows with unsanitized paths
- 0 Nonce checks found
- 0 Capability checks found
CMS Navigation Security Vulnerabilities
CMS Navigation Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
CMS Navigation Attack Surface
WordPress Hooks 6
Maintenance & Trust
CMS Navigation Maintenance & Trust
Maintenance Signals
Community Trust
CMS Navigation Alternatives
Dropdown Menus
dropdown-menus
Display your WordPress menus as a dropdown select box. Great for mobile designs.
Accessible Dropdown Menus
accessible-dropdown-menus
Makes dropdown menus in many WordPress themes keyboard accessible.
Amathia: Accessible Dropdown Menus
amathia
Amathia makes dropdown menus accessible. It adds a button to each dropdown menu, which can be easily clicked to open the submenu.
Navigation menu as Dropdown Widget
navigation-menu-as-dropdown-widget
WordPress plugin which provides a widget with a clickable dropdown of a WordPress navigation menu. It supports one level of parent-child menu's.
Ollie Menu Designer
ollie-menu-designer
Create custom dropdown & mobile menus using WordPress blocks. Design rich, responsive navigation with any block content in the block editor.
CMS Navigation Developer Profile
9 plugins · 108K total installs
How We Detect CMS Navigation
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cms-navigation/css/cms-navigation.css/wp-content/plugins/cms-navigation/js/cms-navigation.js/wp-content/plugins/cms-navigation/js/cms-navigation.jscms-navigation/style.css?ver=cms-navigation/script.js?ver=HTML / DOM Fingerprints
cms-nav-top-menuselectedtrigger<!-- CMS Navigation has been replaced with the WPML plugin - information on how to migrate --><!-- Dismiss this message -->data-cms-navigation-idcms_nav_ie_ver