
Custom Post Type Auto Menu Security & Risk Analysis
wordpress.org/plugins/custom-post-type-auto-menuAutomatically create menu items for your custom post types in your chosen menu and parent menu item.
Is Custom Post Type Auto Menu Safe to Use in 2026?
Generally Safe
Score 85/100Custom Post Type Auto Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'custom-post-type-auto-menu' plugin v1.3.1 presents a generally good security posture based on the provided static analysis. The plugin demonstrates strong adherence to secure coding practices by employing prepared statements for all SQL queries and including nonce and capability checks for its single AJAX handler. There are no identified dangerous functions, file operations, or external HTTP requests, which significantly reduces the potential attack surface. Furthermore, the absence of any recorded vulnerabilities, including CVEs, suggests a history of security diligence or a lack of past exploitability.
However, a notable concern lies in the low percentage of properly escaped output (7%). This indicates that while the plugin handles data interaction securely, there's a risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied or dynamic data is outputted without adequate sanitization or escaping. While taint analysis showed no unsanitized flows, this doesn't entirely negate the XSS risk given the low output escaping percentage; it might imply the data processed by the plugin is not inherently user-controllable in a way that would trigger the taint analysis, or that the analysis was limited.
In conclusion, the plugin is strong in its handling of database interactions and authentication. The primary weakness is the insufficient output escaping, which requires attention to prevent potential XSS. The lack of historical vulnerabilities is a positive sign, but it's crucial to maintain vigilance, especially regarding the identified output escaping issues.
Key Concerns
- Low output escaping percentage
Custom Post Type Auto Menu Security Vulnerabilities
Custom Post Type Auto Menu Code Analysis
SQL Query Safety
Output Escaping
Custom Post Type Auto Menu Attack Surface
AJAX Handlers 1
WordPress Hooks 9
Maintenance & Trust
Custom Post Type Auto Menu Maintenance & Trust
Maintenance Signals
Community Trust
Custom Post Type Auto Menu Alternatives
Custom Post Type UI
custom-post-type-ui
Admin UI for creating custom content types like post types and taxonomies
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
Intuitive Custom Post Order
intuitive-custom-post-order
Intuitively reorder Posts, Pages, Custom Post Types, Taxonomies, and Sites with a simple drag-and-drop interface.
Custom Post Type Permalinks
custom-post-type-permalinks
Edit the permalink of custom post type.
PublishPress Capabilities – User Role Editor, Access Permissions, User Capabilities, Admin Menus
capability-manager-enhanced
PublishPress Capabilities is the access control plugin. You can manage user capabilities, permissions, user roles, admin menus and more.
Custom Post Type Auto Menu Developer Profile
1 plugin · 600 total installs
How We Detect Custom Post Type Auto Menu
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-post-type-auto-menu/assets/js/admin.js/wp-content/plugins/custom-post-type-auto-menu/assets/css/cpt-auto-menu.css/wp-content/plugins/custom-post-type-auto-menu/assets/js/admin.jscustom-post-type-auto-menu/assets/js/admin.js?ver=cpt-auto-menu-style?ver=HTML / DOM Fingerprints
bfp-cpt-auto-menu-admin-scriptdata-nonce-idAjaxSelected