
DEMENU Security & Risk Analysis
wordpress.org/plugins/demenuPlugin para crear una carta digital moderna y sencilla para restaurantes.
Is DEMENU Safe to Use in 2026?
Generally Safe
Score 100/100DEMENU has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "demenu" plugin version 1.0.13 exhibits a generally strong security posture, largely due to its apparent adherence to secure coding practices. The static analysis reveals a minimal attack surface with only one shortcode and no unprotected entry points. Crucially, the plugin demonstrates excellent SQL hygiene by exclusively using prepared statements and a high degree of output escaping, with 98% of outputs being properly sanitized. The absence of known CVEs and a clean vulnerability history further bolster its security profile, suggesting a well-maintained and secure codebase.
However, there are notable areas for improvement that introduce potential, albeit currently unexploited, risks. The complete lack of nonce checks and capability checks across all entry points is a significant concern. While the static analysis indicates no unprotected entry points currently, this absence of built-in WordPress security mechanisms means that if any new functionality were added or existing functionality were to become exposed in the future, it would be inherently vulnerable to various attacks, such as Cross-Site Request Forgery (CSRF) or unauthorized privilege escalation, without explicit defenses. The presence of file operations and external HTTP requests, while not inherently problematic, warrants careful review to ensure they do not introduce vulnerabilities, especially in the absence of robust authorization checks.
Key Concerns
- Missing nonce checks on entry points
- Missing capability checks on entry points
- Presence of file operations with no explicit auth checks
- Presence of external HTTP requests with no explicit auth checks
DEMENU Security Vulnerabilities
DEMENU Release Timeline
DEMENU Code Analysis
Output Escaping
DEMENU Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
DEMENU Maintenance & Trust
Maintenance Signals
Community Trust
DEMENU Alternatives
MenuMaster – Interactive Mobile-First Restaurant Menu Plugin for WooCommerce
menumaster-restaurant-menu
Create mobile-friendly restaurant menus that are easy for customers to access by scanning a QR code. Custom tags and filters make navigation simple, h …
QRMenu Restaurant QR Menu Lite
qrmenu-lite
QRMenu Lite is an advanced online menu tool for restaurants and other food establishments to manage digital menus right on your websites.
wMenu Digital Menu and Restaurant Ordering
wmenu-digital-menu-and-restaurant-ordering
wMenu is restaurant Menu and Ordering plugin. wMenu helps site builders to add restaurant Menu, Wine and Drink list into any WordPress theme.
MenuMax – Digital Restaurant Menus
menumax-digital-restaurant-menus
Create stunning, mobile-responsive digital restaurant menus with drag-and-drop builder, WooCommerce integration, and multi-currency support.
GASTROFIX Menu Plugin
vendomat-gastrofix-menu
Präsentieren Sie ausgewählte Produkte aus der GASTROFIX Kasse direkt auf Ihrer Internet Präsenz. Present selected pdoructs from the GASTROFIX cash re …
DEMENU Developer Profile
1 plugin · 0 total installs
How We Detect DEMENU
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/demenu/assets/public/css/main.css/wp-content/plugins/demenu/assets/libs/swiper/css/swiper-bundle.min.css/wp-content/plugins/demenu/assets/libs/swiper/js/swiper-bundle.min.js/wp-content/plugins/demenu/assets/public/js/main.js/wp-content/plugins/demenu/assets/public/js/main.js/wp-content/plugins/demenu/assets/libs/swiper/js/swiper-bundle.min.jsdemenu-main-css?ver=1.1demenu-main-js?ver=1.0demenu-swiper-css?ver=11.1.0demenu-swiper-js?ver=11.1.0