Flexi Menu – Floating, Vertical, Dropdown & Right Click Menus Security & Risk Analysis

wordpress.org/plugins/flexi-menu

Flexi Menu lets you build floating, vertical, dropdown and right-click menus with ease. Enhance your site’s navigation and user experience.

20 active installs v1.1.1 PHP 7.4+ WP 5.5+ Updated Dec 2, 2025
dropdown-menufloating-menuright-clicksidebar-menuvertical-menu
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Flexi Menu – Floating, Vertical, Dropdown & Right Click Menus Safe to Use in 2026?

Generally Safe

Score 100/100

Flexi Menu – Floating, Vertical, Dropdown & Right Click Menus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The flexi-menu v1.1.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points significantly limits the plugin's attack surface. Furthermore, the high percentage of prepared statements for SQL queries and properly escaped outputs indicate good development practices for handling data and preventing common injection vulnerabilities. The presence of nonce and capability checks, although limited in number, also demonstrates an awareness of WordPress security standards.

However, the taint analysis reveals a potential area of concern. All eight analyzed flows showed unsanitized paths, with three identified as high severity. This suggests that user-supplied data might be processed in a way that could lead to vulnerabilities, even if direct SQL injection or critical output escaping issues were not flagged. The presence of file operations, though only one, warrants careful review in conjunction with the taint analysis to ensure no sensitive files are improperly accessed or manipulated.

The plugin's vulnerability history is a significant strength, with zero recorded CVEs. This pattern indicates a history of stable and likely secure development, suggesting that past issues, if any, have been effectively addressed or avoided. In conclusion, flexi-menu v1.1.1 appears to be a well-developed plugin with a minimal attack surface and a clean vulnerability record. The primary area for caution lies within the taint analysis, where the unsanitized path flows, particularly those flagged as high severity, require further investigation to ensure robust input validation and sanitization.

Key Concerns

  • High severity unsanitized taint flows
  • All analyzed taint flows had unsanitized paths
  • File operation present
Vulnerabilities
None known

Flexi Menu – Floating, Vertical, Dropdown & Right Click Menus Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Flexi Menu – Floating, Vertical, Dropdown & Right Click Menus Code Analysis

Dangerous Functions
0
Raw SQL Queries
6
20 prepared
Unescaped Output
7
345 escaped
Nonce Checks
3
Capability Checks
2
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

77% prepared26 total queries

Output Escaping

98% escaped352 total outputs
Data Flows
8 unsanitized

Data Flow Analysis

8 flows8 with unsanitized paths
menu (classes\Admin\Dashboard.php:158)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Flexi Menu – Floating, Vertical, Dropdown & Right Click Menus Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_initclasses\Admin\AdminActions.php:23
actionadmin_noticesclasses\Admin\AdminNotices.php:26
filterplugin_action_linksclasses\Admin\Dashboard.php:21
filteradmin_footer_textclasses\Admin\Dashboard.php:22
actionadmin_enqueue_scriptsclasses\Admin\Dashboard.php:23
actionadmin_menuclasses\Admin\Dashboard.php:24
actionadmin_menuincludes\class-wow-company.php:20
actionadmin_enqueue_scriptsincludes\class-wow-company.php:21
actionwp_footerpublic\class-wowp-public.php:35
actionwp_enqueue_scriptspublic\class-wowp-public.php:36
Maintenance & Trust

Flexi Menu – Floating, Vertical, Dropdown & Right Click Menus Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 2, 2025
PHP min version7.4
Downloads860

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Flexi Menu – Floating, Vertical, Dropdown & Right Click Menus Developer Profile

Wow-Company

25 plugins · 98K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
236 days
View full developer profile
Detection Fingerprints

How We Detect Flexi Menu – Floating, Vertical, Dropdown & Right Click Menus

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/flexi-menu/vendors/fonticonpicker/css/base/jquery.fonticonpicker.css/wp-content/plugins/flexi-menu/vendors/fonticonpicker/css/themes/dark-grey-theme/jquery.fonticonpicker.darkgrey.css/wp-content/plugins/flexi-menu/vendors/fonticonpicker/js/jquery.fonticonpicker.js/wp-content/plugins/flexi-menu/vendors/fontawesome/css/all.min.css
Script Paths
/wp-content/plugins/flexi-menu/vendors/fonticonpicker/js/jquery.fonticonpicker.js
Version Parameters
flexi-menu/vendors/fonticonpicker/css/base/jquery.fonticonpicker.css?ver=flexi-menu/vendors/fonticonpicker/css/themes/dark-grey-theme/jquery.fonticonpicker.darkgrey.css?ver=flexi-menu/vendors/fonticonpicker/js/jquery.fonticonpicker.js?ver=flexi-menu/vendors/fontawesome/css/all.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
wpie-linkswpie-color-orangewow-plugin-flexi-menu
HTML Comments
Plugin Menu: Flexi Menu
Data Attributes
data-wow-plugin="flexi-menu"data-iddata-paramdata-statusdata-modedata-tag
JS Globals
WOWP_Plugin
FAQ

Frequently Asked Questions about Flexi Menu – Floating, Vertical, Dropdown & Right Click Menus