Dropdown SMU Link Security & Risk Analysis

wordpress.org/plugins/dropdown-smu-style

Create a dropdown with several formats that links to a URL without coding.

10 active installs v1.1 PHP 5.0+ WP 4.9+ Updated Jan 8, 2019
dropdown-menulinkssitemapsmu
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Dropdown SMU Link Safe to Use in 2026?

Generally Safe

Score 85/100

Dropdown SMU Link has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The 'dropdown-smu-style' plugin version 1.1 exhibits a generally good security posture, adhering to several best practices. The absence of known CVEs and the complete reliance on prepared statements for its single SQL query are strong positive indicators. Furthermore, a high percentage of output escaping (87%) suggests developers are mindful of preventing cross-site scripting (XSS) vulnerabilities.

However, the static analysis reveals some areas of concern. The presence of two shortcodes, while not directly exposed as unprotected entry points in the static analysis, represent potential attack vectors if not handled carefully. More significantly, the taint analysis indicates two flows with unsanitized paths, which, despite not being classified as critical or high severity in this instance, warrant attention. The complete lack of nonce checks, combined with two capability checks and a single file operation, suggests potential weaknesses in authentication and authorization mechanisms, particularly if these operations handle sensitive data or user input without robust validation.

The plugin's vulnerability history is clean, which is a significant strength. This pattern of no recorded vulnerabilities, coupled with the good practices observed in the static analysis, suggests a developer with a strong understanding of WordPress security. However, the presence of unsanitized taint flows and the lack of nonce checks highlight that even well-intentioned development can have subtle security gaps. The overall risk is currently low, but there is room for improvement in hardening against potential future threats.

Key Concerns

  • Taint flows with unsanitized paths
  • Shortcodes present as entry points
  • No nonce checks
  • File operations present
Vulnerabilities
None known

Dropdown SMU Link Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Dropdown SMU Link Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Dropdown SMU Link Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
9
60 escaped
Nonce Checks
0
Capability Checks
2
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

87% escaped69 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
settingsPage (DropdownLinks_OptionsManager.php:248)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Dropdown SMU Link Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[smu_dropdown] DropdownLinks_Plugin.php:307
[listdown] DropdownLinks_Plugin.php:312
WordPress Hooks 8
actionadmin_initDropdownLinks_OptionsManager.php:232
actionwp_enqueue_scriptsDropdownLinks_Plugin.php:308
actionwp_enqueue_scriptsDropdownLinks_Plugin.php:309
actionwp_enqueue_scriptsDropdownLinks_Plugin.php:310
actionadmin_menuDropdownLinks_Plugin.php:316
actionwp_footerDropdownLinks_ShortCodeScriptLoader.php:24
actionadmin_noticesdropdown-links.php:52
actionplugins_loadedidropdown-links.php:77
Maintenance & Trust

Dropdown SMU Link Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJan 8, 2019
PHP min version5.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Dropdown SMU Link Developer Profile

webcreativemaster

4 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Dropdown SMU Link

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dropdown-smu-style/css/dropdown_style.css/wp-content/plugins/dropdown-smu-style/js/dropdown.js
Script Paths
/wp-content/plugins/dropdown-smu-style/js/dropdown.js
Version Parameters
dropdown-smu-style/css/dropdown_style.css?ver=dropdown-smu-style/js/dropdown.js?ver=

HTML / DOM Fingerprints

CSS Classes
oncontentdrophalimdropbtnpeterpants
Data Attributes
onclick="window.location.href=''onclick="winonmouseover="this.style.backgroundColor='
Shortcode Output
[smu_dropdown bgcolor=[smu_dropdown bgcolor='#b3b3b3'[smu_dropdown bgcolor='#b3b3b3' bghover='#ffffff'[smu_dropdown bgcolor='#b3b3b3' bghover='#ffffff' bordercolor='#b72828'
FAQ

Frequently Asked Questions about Dropdown SMU Link