Fly Nav Mobile Security & Risk Analysis

wordpress.org/plugins/fly-nav-mobile

Fastest WordPress Mobile Menu. Pure CSS, zero JS. Slide-out hamburger menu or app-style bottom navigation. Sticky header & visual selector.

0 active installs v2.4.2 PHP 7.2+ WP 5.0+ Updated Dec 25, 2025
bottom-navigationhamburger-menumobile-menuslide-out-menusticky-menu
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Fly Nav Mobile Safe to Use in 2026?

Generally Safe

Score 100/100

Fly Nav Mobile has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "fly-nav-mobile" plugin v2.4.2 exhibits a generally strong security posture with excellent practices in most areas. The plugin demonstrates a commitment to security by using prepared statements for all SQL queries and properly escaping a very high percentage of its output. Furthermore, the absence of any recorded vulnerabilities, including critical or high severity ones, and the lack of bundled libraries suggest a well-maintained and secure codebase. The plugin also correctly implements a good number of nonce and capability checks, indicating awareness of common WordPress attack vectors.

However, a significant concern arises from the static analysis, which reveals two AJAX handlers, with one lacking any authentication checks. This unprotected entry point presents a direct attack vector that could be exploited if a malicious user can trigger it. While taint analysis shows no unsanitized paths, the existence of an unprotected AJAX handler is a critical weakness that overrides the otherwise positive security indicators.

In conclusion, "fly-nav-mobile" v2.4.2 benefits from robust coding practices regarding database interactions and output handling, and a clean vulnerability history. The primary weakness is the single unprotected AJAX handler, which significantly increases the risk profile. Addressing this specific vulnerability should be the immediate priority to improve the plugin's overall security.

Key Concerns

  • Unprotected AJAX handler
Vulnerabilities
None known

Fly Nav Mobile Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Fly Nav Mobile Release Timeline

v2.4.2Current
v2.4.1
v2.4.0
v2.0.1
v1.1.2
v1.1.1
Code Analysis
Analyzed Apr 16, 2026

Fly Nav Mobile Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
149 escaped
Nonce Checks
5
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

97% escaped153 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

3 flows
fnmm_handle_ajax_save_settings (fly-nav-mobile.php:119)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Fly Nav Mobile Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 2

authwp_ajax_fnmm_save_settingsfly-nav-mobile.php:50
authwp_ajax_fnmm_save_settingsfly-nav-mobile.php:145
WordPress Hooks 17
filterplugin_action_links_fly-nav-mobile/fly-nav-mobile.phpbackend/class-fly-nav-mobile-backend.php:7
actionadmin_menufly-nav-mobile.php:41
actionadmin_initfly-nav-mobile.php:42
actionadmin_enqueue_scriptsfly-nav-mobile.php:43
actionwp_enqueue_scriptsfly-nav-mobile.php:46
actionwp_footerfly-nav-mobile.php:47
filterdetermine_current_userfly-nav-mobile.php:73
filtershow_admin_barfly-nav-mobile.php:76
actionwp_enqueue_scriptsfly-nav-mobile.php:79
actionwp_headfly-nav-mobile.php:87
actionplugins_loadedfly-nav-mobile.php:98
filterdetermine_current_userfly-nav-mobile.php:112
actioninitfly-nav-mobile.php:115
actionadmin_initfly-nav-mobile.php:178
actionwp_enqueue_scriptspublic/class-fly-nav-mobile-public.php:13
actionwp_enqueue_scriptspublic/class-fly-nav-mobile-public.php:14
actionwp_headpublic/class-fly-nav-mobile-public.php:16
Maintenance & Trust

Fly Nav Mobile Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 25, 2025
PHP min version7.2
Downloads1K

Community Trust

Rating80/100
Number of ratings1
Active installs0
Developer Profile

Fly Nav Mobile Developer Profile

Aamir Faiz

5 plugins · 90 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Fly Nav Mobile

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fly-nav-mobile/public/css/fly-nav-mobile.css/wp-content/plugins/fly-nav-mobile/public/js/fly-nav-mobile.js
Script Paths
/wp-content/plugins/fly-nav-mobile/public/js/fly-nav-mobile.js
Version Parameters
fly-nav-mobile/public/css/fly-nav-mobile.css?ver=fly-nav-mobile/public/js/fly-nav-mobile.js?ver=

HTML / DOM Fingerprints

CSS Classes
fnmm-mobile-menufnmm-menu-toggle
HTML Comments
Fly Nav Mobile SettingsFly Nav Mobile PreviewFly Nav Mobile Menu Output StartFly Nav Mobile Menu Output End
Data Attributes
data-fnmm-toggle-selectordata-fnmm-close-selectordata-fnmm-menu-iddata-fnmm-menu-class
JS Globals
fnmm_globals
FAQ

Frequently Asked Questions about Fly Nav Mobile