Drag & Drop Menu Items Security & Risk Analysis

wordpress.org/plugins/drag-drop-menu-items

Add WP Menu Items By Dragging It & Dropping into Menu Items List Area.

90 active installs v2.0.2 PHP 8.0+ WP 5.6+ Updated Dec 10, 2025
add-menu-itemsdrag-and-dropnav-menu-itemsnav-menu-items-editwp-nav-menus
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Drag & Drop Menu Items Safe to Use in 2026?

Generally Safe

Score 100/100

Drag & Drop Menu Items has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The static analysis of the "drag-drop-menu-items" plugin version 2.0.2 indicates a strong security posture. The plugin demonstrates excellent adherence to secure coding practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and properly escaping all output. Furthermore, it has no file operations, external HTTP requests, and a completely clean slate regarding known vulnerabilities, with zero CVEs recorded. The absence of any identified taint analysis findings further strengthens this positive assessment.

While the lack of any identified vulnerabilities or insecure coding practices is commendable, the most notable aspect of the static analysis is the complete absence of entry points such as AJAX handlers, REST API routes, shortcodes, and cron events. This suggests that the plugin, in its current form, might not offer any user-facing functionality that would typically be exposed to external input. This is a significant strength in reducing the attack surface. However, it also raises questions about the plugin's actual functionality and how it's intended to be used. If there are no entry points, it's difficult to ascertain its purpose or potential impact on security.

In conclusion, based solely on the provided data, the "drag-drop-menu-items" plugin v2.0.2 appears to be exceptionally secure. The developers have followed best practices diligently. The lack of any reported vulnerabilities or static analysis red flags is a significant positive. The primary point of consideration is the extremely limited attack surface, which, while secure, could imply a very niche or internal functionality. Without further context on the plugin's intended use, it is difficult to assign any negative deductions.

Vulnerabilities
None known

Drag & Drop Menu Items Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Drag & Drop Menu Items Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

Drag & Drop Menu Items Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_enqueue_scriptsincludes\class-drag-drop-menu-items.php:115
Maintenance & Trust

Drag & Drop Menu Items Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 10, 2025
PHP min version8.0
Downloads6K

Community Trust

Rating100/100
Number of ratings1
Active installs90
Developer Profile

Drag & Drop Menu Items Developer Profile

Sajjad Hossain Sagor

32 plugins · 10K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
139 days
View full developer profile
Detection Fingerprints

How We Detect Drag & Drop Menu Items

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/drag-drop-menu-items/admin/css/admin.css/wp-content/plugins/drag-drop-menu-items/admin/js/admin.js
Script Paths
admin/js/admin.js
Version Parameters
drag-drop-menu-items?ver=admin.js?ver=admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
drag-drop-menu-items-wrap
Data Attributes
data-nonce
JS Globals
DragDropMenuItems
FAQ

Frequently Asked Questions about Drag & Drop Menu Items