
Custom Menu Security & Risk Analysis
wordpress.org/plugins/custom-menuThis plugin allows you to display a custom menu that you've created in your theme's "Menus" section in a post or page.
Is Custom Menu Safe to Use in 2026?
Use With Caution
Score 63/100Custom Menu has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'custom-menu' plugin v1.8 exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and has a relatively small attack surface with no unprotected entry points found in the static analysis. It also performs capability checks and handles file operations, which are common necessities for plugins. However, significant concerns arise from the complete lack of output escaping, meaning all four identified output points are vulnerable to Cross-Site Scripting (XSS) attacks. Additionally, the absence of nonce checks on any entry points is a critical oversight, potentially allowing for Cross-Site Request Forgery (CSRF) if other vulnerabilities are present or if the plugin's functionality is sensitive. The vulnerability history, with one currently unpatched medium severity CVE for XSS discovered in the near future, reinforces the output escaping issue and suggests a pattern of input sanitization deficiencies.
Key Concerns
- Unpatched CVE
- No output escaping
- No nonce checks
Custom Menu Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Custom Menu <= 1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
Custom Menu Code Analysis
Output Escaping
Custom Menu Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Custom Menu Maintenance & Trust
Maintenance Signals
Community Trust
Custom Menu Alternatives
AGCA – Custom Dashboard & Login Page
ag-custom-admin
CHANGE: admin menu, login page, admin bar, dashboard widgets, custom colors, custom CSS & JS, logo & images
Custom Menu Wizard Widget
custom-menu-wizard
Show branches or levels of your menu in a widget, or in content using a shortcode, with full customisation.
Zen Menu Logic
zen-menu-logic
Zen Menu Logic allows the user to select any of several custom menus to appear on a per page basis.
F12 Floating Menu, sticky menu for WordPress
f12-floating-menu
Easily add unlimited floating/sticky menus to your Website. The F12 Floating Menu comes with an easy-to-use interface, allowing you to have the full c …
The Menu: Custom mobile navigation with icons
the-menu
Create beautiful mobile navigation menus with custom icons, role-based visibility, and extensive style options for your WordPress site.
Custom Menu Developer Profile
2 plugins · 410 total installs
How We Detect Custom Menu
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-menu/css/admin.css/wp-content/plugins/custom-menu/js/admin.js/wp-content/plugins/custom-menu/js/admin.jscustom-menu/css/admin.css?ver=custom-menu/js/admin.js?ver=HTML / DOM Fingerprints
[menu name=[menu name=[menu name=