Dynamic Latest Post in Nav Menu Security & Risk Analysis

wordpress.org/plugins/dynamic-latest-post-in-nav-menu

Add the link to dynamic latest post page, and the Archive page to Nav Menu.

400 active installs v1.1.1 PHP + WP 3.5.0+ Updated Nov 12, 2015
nav-menu
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Dynamic Latest Post in Nav Menu Safe to Use in 2026?

Generally Safe

Score 85/100

Dynamic Latest Post in Nav Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The 'dynamic-latest-post-in-nav-menu' plugin version 1.1.1 exhibits a generally strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the plugin demonstrates good practices by exclusively using prepared statements for its single SQL query and by properly escaping the majority of its output. The lack of any file operations, external HTTP requests, and no recorded vulnerability history or known CVEs further contributes to its favorable security profile.

However, a notable concern is the complete absence of nonce checks and capability checks. While the current attack surface is minimal, any future expansion or modification of the plugin's functionality without these fundamental security checks could introduce vulnerabilities. The taint analysis indicating zero flows with unsanitized paths is positive, but this is in conjunction with zero total flows analyzed, suggesting limited test coverage in that area. Overall, the plugin is currently well-secured due to its limited scope and good data handling practices, but the lack of built-in access control mechanisms presents a potential area for future risk if the plugin's complexity increases.

Key Concerns

  • No nonce checks present
  • No capability checks present
  • Only 67% of output properly escaped
Vulnerabilities
None known

Dynamic Latest Post in Nav Menu Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Dynamic Latest Post in Nav Menu Release Timeline

v1.1.1Current
v1.1.0
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Dynamic Latest Post in Nav Menu Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
2
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

67% escaped6 total outputs
Attack Surface

Dynamic Latest Post in Nav Menu Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_head-nav-menus.phpdynamic-latest-post-in-nav-menu.php:20
filterwp_setup_nav_menu_itemdynamic-latest-post-in-nav-menu.php:21
filterwp_nav_menu_objectsdynamic-latest-post-in-nav-menu.php:22
filterwp_get_nav_menu_itemsdynamic-latest-post-in-nav-menu.php:23
Maintenance & Trust

Dynamic Latest Post in Nav Menu Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedNov 12, 2015
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings3
Active installs400
Developer Profile

Dynamic Latest Post in Nav Menu Developer Profile

hijiri

3 plugins · 400K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
364 days
View full developer profile
Detection Fingerprints

How We Detect Dynamic Latest Post in Nav Menu

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
dlpinm-archivedlpinm-latestdlpinm-checklist
Data Attributes
name="add-dlpinm-menu-item"id="submit-dlpinm-archive"id="submit-dlpinm-latest"
FAQ

Frequently Asked Questions about Dynamic Latest Post in Nav Menu