
Custom Page Menus Security & Risk Analysis
wordpress.org/plugins/custom-page-menusCustom Page Menus plugin allows custom menus to be defined on a per-page basis.
Is Custom Page Menus Safe to Use in 2026?
Generally Safe
Score 85/100Custom Page Menus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "custom-page-menus" plugin v1.0 exhibits a generally concerning security posture despite an absence of known historical vulnerabilities and a seemingly small attack surface. While the static analysis reports zero AJAX handlers, REST API routes, shortcodes, or cron events, indicating a limited direct entry point for attackers, the code itself reveals significant weaknesses. The presence of the `create_function` dangerous function is a red flag, as it's a known source of potential code injection vulnerabilities if not handled with extreme care and input validation. Furthermore, the critically low 6% of properly escaped outputs across 32 output points suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the user interface. The taint analysis showing two unsanitized paths, even without critical or high severity, points to potential data leakage or manipulation risks. The complete lack of nonce and capability checks on all identified entry points (though zero in number) is also a notable weakness. The plugin's vulnerability history being completely clear is a positive sign, but it does not negate the inherent risks identified in the code analysis, which are substantial.
Key Concerns
- Presence of dangerous function create_function
- Low percentage of properly escaped output
- Unsanitized paths found in taint analysis
- No nonce checks found
- No capability checks found
Custom Page Menus Security Vulnerabilities
Custom Page Menus Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Custom Page Menus Attack Surface
WordPress Hooks 2
Maintenance & Trust
Custom Page Menus Maintenance & Trust
Maintenance Signals
Community Trust
Custom Page Menus Alternatives
Zen Menu Logic
zen-menu-logic
Zen Menu Logic allows the user to select any of several custom menus to appear on a per page basis.
AGCA – Custom Dashboard & Login Page
ag-custom-admin
CHANGE: admin menu, login page, admin bar, dashboard widgets, custom colors, custom CSS & JS, logo & images
Advanced Sidebar Menu
advanced-sidebar-menu
Fully automatic sidebar menus.
Custom Menu Wizard Widget
custom-menu-wizard
Show branches or levels of your menu in a widget, or in content using a shortcode, with full customisation.
Easy Sidebar Menu Widget
easy-sidebar-menu-widget
Add WordPress Dropdown Menu Widget easily! Upgrade your sidebar menus to responsive dropdown widget now!
Custom Page Menus Developer Profile
6 plugins · 400 total installs
How We Detect Custom Page Menus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
custom-pages-divhowtoOmmitted by WP ----- DO NOT REMOVE !!name="custom-page-menu-title"name="add"name="remove"