Custom Adminbar Menus Security & Risk Analysis

wordpress.org/plugins/custom-adminbar-menus

This is a simple plugin for adding custom navigation menus to your WordPress Adminbar.

300 active installs v19.05 PHP + WP 3.3+ Updated May 2, 2019
adminbarcustom-adminbar-menusmenunav-menutoolbar
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Custom Adminbar Menus Safe to Use in 2026?

Generally Safe

Score 85/100

Custom Adminbar Menus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The custom-adminbar-menus plugin v19.05 exhibits a generally strong security posture based on the static analysis. The absence of identified dangerous functions, SQL queries utilizing prepared statements exclusively, and a lack of file operations or external HTTP requests are all positive indicators. Furthermore, the plugin appears to have no known vulnerabilities, with a clean history of CVEs, suggesting a commitment to maintaining a secure codebase.

However, there are areas for improvement. A significant concern is the complete absence of nonce checks and capability checks. While the static analysis reported zero entry points without authentication, the lack of these fundamental WordPress security mechanisms means that if any entry points were to be introduced in future versions or through potential unforeseen interactions, they might be vulnerable to attacks. The 75% rate of properly escaped output also indicates a small but present risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled correctly in the remaining 25% of outputs.

In conclusion, custom-adminbar-menus v19.05 presents a low immediate risk due to its clean vulnerability history and good practices in handling SQL. Nevertheless, the absence of nonce and capability checks is a notable weakness that could be exploited if the attack surface were to expand. Addressing these checks would significantly harden the plugin's security.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Unescaped output (25%)
Vulnerabilities
None known

Custom Adminbar Menus Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Custom Adminbar Menus Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

75% escaped12 total outputs
Attack Surface

Custom Adminbar Menus Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterplugin_row_metaindex.php:27
filteradmin_initindex.php:91
actioninitindex.php:119
actionwp_before_admin_bar_renderindex.php:233
Maintenance & Trust

Custom Adminbar Menus Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedMay 2, 2019
PHP min version
Downloads10K

Community Trust

Rating96/100
Number of ratings9
Active installs300
Developer Profile

Custom Adminbar Menus Developer Profile

Linesh Jose

3 plugins · 510 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Custom Adminbar Menus

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
cam-adminabr-postscam-adminabr-pagescam-adminabr-themescam-adminabr-pluginscam-adminabr-toolscam-adminabr-userscam-adminabr-settingscam-adminabr-new-theme+2 more
Data Attributes
id="cam-additional-shortcuts-label"
FAQ

Frequently Asked Questions about Custom Adminbar Menus